Executive brief
Grackle AI's Model Context Protocol (MCP) components contain a security flaw where automated agents can perform actions outside their intended scope. A malicious or compromised agent could delete, modify, or view tasks and sessions belonging to other users or agents. This could lead to unauthorized data access, permanent loss of work, or disruption of automated workflows.
Technical details
The vulnerability arises because authorization for scoped MCP callers is enforced inconsistently at the tool layer rather than centrally. The MCP server authenticates outbound gRPC calls using a full server API key, while backend handlers in 'plugin-core' lack caller-based authorization, relying entirely on the tool layer to validate ancestry and workspace boundaries. Several tools (task_update, task_delete, session_kill, etc.) fail to implement these checks, allowing an attacker to provide arbitrary IDs to manipulate resources. Additionally, workspaceless tokens fail-open to grant access to all workspaces, and token revocation logic is unimplemented, leaving compromised tokens valid for their full 24-hour TTL. An attacker with network access and low privileges (a scoped agent) can achieve full unauthorized control over tasks and sessions.
Affected products
- Grackle AI @grackle-ai/mcp <= 0.132.1
- Grackle AI @grackle-ai/plugin-core <= 0.132.1
- Grackle AI @grackle-ai/auth <= 0.132.1
Timeline
- 2026-05-29: disclosed
- 2026-07-02: advisory