Medium severity5.0NVD Advisory· Published Sep 21, 2026· Updated Sep 21, 2026
CVE-2026-77518
CVE-2026-77518
Description
MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal workspace user who knows another user's active MCP tool_id in the same workspace can retrieve the hidden tool through the tool-detail route because it does not apply the per-resource authorization used by the list route. The response includes Tool.code, which may contain MCP server configuration and headers, and an attacker who can create or edit an attacker-owned workflow can place the same foreign mcp_tool_id in a workflow mcp-node so workflow debug uses the owner's MCP configuration without verifying permission to use that tool. No fixed version is available as of this review.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.