CVE-2025-51479: ONYX Authorization Bypass in Enterprise Edition Group Management API
Authorization bypass vulnerability in ONYX Enterprise Edition allowing curators to manipulate groups outside their authorized scope.
Artemiy Malyshau
Vulnerability research, CVE write-ups and practical guides from the team building Gecko. Written for the engineers who have to fix the thing, not just triage it.
Authorization bypass vulnerability in ONYX Enterprise Edition allowing curators to manipulate groups outside their authorized scope.
Artemiy Malyshau
Local file inclusion vulnerability in Dagster’s gRPC server allowing arbitrary file reading through path traversal in notebook data endpoint.
Artemiy Malyshau
Remote code execution vulnerability in Letta’s tool execution endpoint through unsafe Python code execution in inadequate sandbox.
Artemiy Malyshau
Stored cross-site scripting vulnerability in AIM Reports allowing malicious Python code to execute arbitrary JavaScript in users’ browsers.
Artemiy Malyshau
Arbitrary file overwrite vulnerability in ONNX library’s save_external_data function through path traversal attacks.
Artemiy Malyshau
SQL injection vulnerability in DB-GPT 0.7.0 despite fixes for prior CVEs, affecting multiple database endpoints.
Artemiy Malyshau
Showing 37 - 42 of 47 articles
Occasional updates and insights. No spam; unsubscribe anytime.