Junglewise Threat Intelligence

@grackle-ai/mcp workspace authorization bypass in knowledge_search tool

Severity: medium · CVSS 4 · Published 2026-03-25

Technologies: @grackle-ai/mcp (npm). Vendors: npm.

Executive brief

@grackle-ai/mcp is a library for managing AI coding agents. A workspace authorization bypass in the knowledge_search and knowledge_get_node tools allows scoped agents assigned to one workspace to access and retrieve sensitive knowledge graph data from other workspaces by supplying arbitrary workspace IDs, resulting in cross-workspace data leakage.

Technical details

The knowledge_search and knowledge_get_node MCP tool handlers lack authContext validation and do not enforce workspace isolation, allowing scoped agents to bypass authorization boundaries. The vulnerable code in packages/mcp/src/tools/knowledge.ts (lines 146-169 for knowledge_search and 244-283 for knowledge_get_node) accepts user-supplied workspaceId parameters without restricting them to the authenticated user's assigned workspace. In contrast, the knowledge_create_node handler correctly implements workspace scoping by checking authContext and overriding supplied workspace IDs for scoped callers. An attacker with a scoped agent token can exploit this by providing arbitrary workspaceId values to access data from other workspaces. The fix requires adding authContext parameter validation to both handlers and enforcing workspace scoping logic similar to knowledge_create_node, with explicit workspace ID override for scoped callers.

Affected products

  • Grackle AI @grackle-ai/mcp <= 0.70.1

Timeline

  • 2026-03-25: disclosed
  • 2026-03-25: patched: Fix released in version 0.70.2

References

Related threats