📦 Onyx

by Onyx

🔍 What is Onyx?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-7767

HIGH CVSS 8.1 Mar 20, 2025

An improper access control vulnerability in danswer-ai/danswer v0.3.94 allows the first user created in the system to view, modify, and delete chats created by an Admin. This affects all deployments u...

CVE-2025-7894

MEDIUM CVSS 6.3 Jul 20, 2025

This critical SQL injection vulnerability in Onyx's chat interface allows attackers to execute arbitrary SQL commands through the generate_simple_sql function. It affects Onyx versions up to 0.29.1 an...

CVE-2024-9612

MEDIUM CVSS 6.5 Mar 20, 2025

This vulnerability allows attackers to bypass front-end visibility restrictions by directly calling the search API, even when administrators have hidden the search page. Regular users who should be bl...