CVE-2026-85178 PUBLISHED

Helicone Cross-Tenant Provider Key Disclosure via Missing Organization Filter

Assigner: VulnCheck
Reserved: 03.09.2026 Published: 03.09.2026 Updated: 03.09.2026

Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider credentials for other tenants, including plaintext OpenAI, Anthropic, and Bedrock API keys.

Metrics

CVSS Vector: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:H/SI:N/SA:N
CVSS Score: 8.3

Product Status

Vendor Helicone
Product helicone
Versions Default: unaffected
  • affected from 0 to ca34549ea56f7ed587843f82d9cc19baa1f36ba4 (excl.)

Credits

  • George Chen reporter

References

Problem Types

  • Authorization Bypass Through User-Controlled Key CWE