MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, then query the target Document by document_id or Paragraph by paragraph_id withou
| 厂商 | 产品 | 版本范围 | 状态 |
|---|---|---|---|
| 1Panel-dev | MaxKB | >= 2.0.0, <= 2.10.2-lts |
affected |
尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。
| 厂商 | 产品 | 影响版本 | CPE | 订阅 |
|---|---|---|---|---|
| 1Panel-dev | MaxKB | >= 2.0.0, <= 2.10.2-lts | - |
|
| # | POC 描述 | 源链接 | 神龙链接 |
|---|
未找到公开 POC。
登录以生成 AI POC| CVE-2026-77521 | 10.0 CRITICAL | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-79916 | 9.1 CRITICAL | MaxKB AWS Bedrock model credential injection leads to remote code execution |
| CVE-2026-77523 | 7.4 HIGH | MaxKB: Cross-workspace model parameter form write |
| CVE-2026-79917 | 6.5 MEDIUM | MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user |
| CVE-2026-79919 | 6.3 MEDIUM | MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path c |
| CVE-2026-79918 | 6.3 MEDIUM | MaxKB: Sandbox escape via unhooked fexecve |
| CVE-2026-77520 | 5.4 MEDIUM | MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to i |
| CVE-2026-77516 | 5.4 MEDIUM | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path |
| CVE-2026-77519 | 5.4 MEDIUM | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` |
| CVE-2026-77518 | 5.0 MEDIUM | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflo |
| CVE-2026-77522 | 4.3 MEDIUM | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fo |
| CVE-2026-77525 | 4.2 MEDIUM | MaxKB: Management chat-record routes trust path application_id but load ChatRecord by glob |
暂无评论