Executive brief
Maxun, an open-source automation platform, contains a security flaw that allows one user to access or modify data belonging to other users. An attacker with a standard account could steal sensitive third-party access tokens (such as Google or Airtable) or interfere with the automated 'robots' created by other customers. This could lead to unauthorized data access, service disruption, and the compromise of connected business accounts.
Technical details
A cross-tenant Insecure Direct Object Reference (IDOR) vulnerability exists in Maxun versions prior to 0.0.42 due to missing authorization checks in the storage and webhook API handlers. The root cause is a failure to validate ownership of resources (CWE-862), where API endpoints like /robots would return all records instead of scoping results to the authenticated user's ID. A remote attacker with low-privileged credentials can exploit this to read plaintext OAuth tokens for Google and Airtable, or modify, delete, and execute robots belonging to other tenants. The issue was addressed in version 0.0.42 by enforcing user-id scoping across all robot-related API endpoints.
Affected products
- getmaxun Maxun < 0.0.42
Timeline
- 2026-05-25: disclosed: Reported via email
- 2026-06-05: patched: Fix committed to repository
- 2026-06-25: advisory: NVD and VulnCheck advisories published