---
id: CVE-2026-85178
title: >-
  Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET
  /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's
  organization against the vault key's organization identifier
summary: >-
  Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET
  /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's
  organization against the vault key's organization identifier. Attackers with
  admin or owne…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: Helicone
product: helicone
affected:
  - helicone < ca34549ea56f7ed587843f82d9cc19baa1f36ba4
published: '2026-09-03'
updated: '2026-09-17'
sourceUpdated: '2026-09-17T18:17:11.387'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-85178'
references:
  - url: 'https://github.com/Helicone/helicone'
    label: disclosure@vulncheck.com
  - url: >-
      https://github.com/Helicone/helicone/commit/ca34549ea56f7ed587843f82d9cc19baa1f36ba4
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Helicone/helicone/issues/5712'
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/helicone-cross-tenant-provider-key-disclosure-via-missing-organization-filter
    label: disclosure@vulncheck.com
  - url: 'https://github.com/Helicone/helicone/issues/5712'
    label: 134c704f-9b21-4f2e-91b3-4a467353bcc0
tags:
  - nvd
  - cve.org
  - exploit-available
exploitAvailable: true
ssvc:
  exploitation: poc
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-03T14:40:59.326415Z'
epss: 0.00238
epssPercentile: 0.15168
ingestedAt: '2026-09-17T18:25:15.988Z'
---

## Overview

Helicone's VaultManager.getDecryptedProviderKeyById() function in the GET /v1/vault/key/{providerKeyId} endpoint fails to validate the requester's organization against the vault key's organization identifier. Attackers with admin or owner privileges in any organization can retrieve decrypted upstream provider credentials for other tenants, including plaintext OpenAI, Anthropic, and Bedrock API keys.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
