Executive brief
MaxKB is an open-source AI assistant platform that allows administrators to grant or deny individual workspace members access to specific tools. From versions 2.0.0 through 2.9.2, a low-privilege member denied access to a tool can still execute it by embedding it into a workflow or agent application, and receive the tool's encrypted server credentials. This allows attackers to bypass authorization controls and gain access to sensitive credentials they should not have.
Technical details
The vulnerability is a missing authorization check (CWE-862/CWE-639) in the agent and workflow tool-dispatch code path. While dedicated tool routes enforce per-tool permissions via WorkspaceUserResourcePermission, the workflow and agent dispatch paths in base_tool_lib_node.py and base_tool_node.py skip this check and execute tools with server-side-injected credentials. An authenticated low-role workspace member can bind a denied tool via tool_ids, skill_tool_ids, or mcp_tool_ids without per-tool validation, execute it through workflow dispatch, and receive decrypted RSA-encrypted init_params carrying the tool's secrets.
Affected products
- 1Panel MaxKB 2.0.0 through 2.9.2
Timeline
- 2026-09-21: disclosed