Authorization Flaw in MaxKB Open-Source AI Assistant
CVE-2026-77518
What is CVE-2026-77518?
MaxKB, an open-source AI assistant designed for enterprise use, contains a significant authorization flaw that impacts versions up to 2.10.2-lts. In this vulnerability, a regular workspace user can gain unauthorized access to another user's hidden MCP tool if they know its active tool_id. The flaw arises due to the lack of per-resource authorization for the tool-detail route, allowing attackers to retrieve sensitive server configurations and headers. By exploiting the ability to create or modify workflows, an attacker could integrate a foreign mcp_tool_id into their workflow, potentially utilizing another user's MCP configuration without appropriate permissions. Currently, no patched version is available to rectify this issue.
Affected Version(s)
MaxKB <= 2.10.2-lts
