Executive brief
MaxKB is an open-source AI assistant platform that stores configuration parameters for language models. An authenticated attacker can exploit a missing authorization check to read or overwrite model parameter defaults belonging to other workspaces, potentially poisoning model settings that affect workflows and outputs across the platform.
Technical details
The model parameter form endpoint performs workspace-level authorization checking but the ModelSerializer.ModelParams class queries models by ID alone, omitting workspace_id filtering. An authenticated user with model read permission in any workspace can call /workspace/{attacker_workspace}/model/{victim_model_id}/model_params_form with a known victim model ID to read or PUT malicious parameters. This requires authentication and knowledge of a target model ID but allows cross-workspace integrity and confidentiality violations.
Affected products
- 1Panel-dev MaxKB 2.10.3-lts and earlier
Timeline
- 2026-09-21: disclosed: GitHub Security Advisory GHSA-g888-8cvh-9284 published
- 2026-09-02: other: Advisory privately reported to MaxKB security team