Junglewise Threat Intelligence

Grackle AI MCP fail-open authorization and IDOR in tool layer

Severity: high · CVSS 8.7 · Published 2026-07-02

Technologies: @grackle-ai/mcp (npm). Vendors: npm.

Executive brief

Grackle AI's Model Context Protocol (MCP) components contain a security flaw where automated agents can perform actions outside their intended scope. A malicious or compromised agent could delete, modify, or view tasks and sessions belonging to other users or agents. This could lead to unauthorized data access, permanent loss of work, or disruption of automated workflows.

Technical details

The vulnerability arises because authorization for scoped MCP callers is enforced inconsistently at the tool layer rather than centrally. The MCP server authenticates outbound gRPC calls using a full server API key, while backend handlers in 'plugin-core' lack caller-based authorization, relying entirely on the tool layer to validate ancestry and workspace boundaries. Several tools (task_update, task_delete, session_kill, etc.) fail to implement these checks, allowing an attacker to provide arbitrary IDs to manipulate resources. Additionally, workspaceless tokens fail-open to grant access to all workspaces, and token revocation logic is unimplemented, leaving compromised tokens valid for their full 24-hour TTL. An attacker with network access and low privileges (a scoped agent) can achieve full unauthorized control over tasks and sessions.

Affected products

  • Grackle AI @grackle-ai/mcp <= 0.132.1
  • Grackle AI @grackle-ai/plugin-core <= 0.132.1
  • Grackle AI @grackle-ai/auth <= 0.132.1

Timeline

  • 2026-05-29: disclosed
  • 2026-07-02: advisory

References

Related threats