PT-2026-38661 · Onyx · Onyx
Abdrrahimdahmani
·
Published
2026-05-08
·
Updated
2026-05-12
·
CVE-2026-42277
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Onyx versions prior to 3.0.9
Onyx versions prior to 3.1.6
Onyx versions prior to 3.2.6
Description
The 'GET /chat/file/{file id}' endpoint allows any authenticated user to download files uploaded by other users. While the system verifies that the requester is authenticated, it fails to check if the requested file belongs to the user. An attacker with a file UUID can access confidential documents and chat attachments.
Recommendations
Update to version 3.0.9
Update to version 3.1.6
Update to version 3.2.6
As a temporary workaround, restrict access to the 'GET /chat/file/{file id}' endpoint.
Exploit
Fix
IDOR
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Onyx