Authentication Bypass in MaxKB Open-Source AI Assistant
CVE-2026-77519
5.4MEDIUM
What is CVE-2026-77519?
MaxKB, an open-source AI assistant, is vulnerable to an authentication bypass that allows the initialization of the MCP endpoint with a non-permanent application key even after its expiration. The vulnerability arises due to insufficient checks on the application API key, where only its secret and active status are considered. As a result, an attacker can exploit this weakness to access application tool metadata, invoke services, and create persistent chat states, despite restrictions that would normally apply to expired keys. There is currently no fixed version.
Affected Version(s)
MaxKB <= 2.10.2-lts
