Impact
Onyx 4.6.6 allows any authenticated user to read custom tool credentials that are stored in custom_headers. By accessing GET /tool or GET /tool/{tool_id} endpoints, an attacker can retrieve plaintext authorization headers, including third‑party API keys. These keys can then be used to authenticate directly with upstream services, enabling unauthorized access or data exfiltration.
Affected Systems
The vulnerability impacts the Onyx application produced by onyx-dot-app. Version 4.6.6 is affected; any instance of that exact version running without a newer patched release is at risk.
Risk and Exploitability
With a CVSS score of 7.1, the vulnerability is considered a medium severity risk. EPSS data is not available, so the current likelihood of exploitation is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers need only authenticated access to the host to trigger the disclosure; no special privileges beyond standard authentication are required. The straightforward HTTP request path makes the exploit trivial for anyone who can log in, so the risk is real and actionable.
OpenCVE Enrichment