Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-77520— MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application

Quick assessment

Affected
1Panel-dev MaxKB
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from the homepage application question-ranking endpoint when the published victim application has ranki

CVSS 5.4 · Medium EPSS 0.17% · P7

Affected Version Matrix 1

VendorProduct Version RangeStatus
1Panel-dev MaxKB <= 2.10.2-lts affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-77520

Vulnerability Information

Shenlong is analyzing...


Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application
Source: CVE Program / CVE List V5
Vulnerability Description
MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from the homepage application question-ranking endpoint when the published victim application has ranking activity in the selected date range and the attacker knows or guesses its name, even though direct application detail and debug-open routes deny access. An attacker who can create and publish a workflow application can place the disclosed identifier in an attacker-owned workflow application-node, trigger that workflow, receive output generated by the victim application, and create durable application_chat and application_chat_record rows under the victim application because save and runtime paths do not verify permission to use the referenced application. No fixed version is available as of this review.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
1Panel-dev MaxKB <= 2.10.2-lts -

II. Public POCs for CVE-2026-77520

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-77520

登录查看更多情报信息。

Other References for CVE-2026-77520 (1)

Same Patch Batch · 1Panel-dev · 2026-09-21 · 13 CVEs total

CVE-2026-77521 10.0 CRITICAL MaxKB: Prompt-injectable agent can lead to command execution
CVE-2026-79916 9.1 CRITICAL MaxKB AWS Bedrock model credential injection leads to remote code execution
CVE-2026-77523 7.4 HIGH MaxKB: Cross-workspace model parameter form write
CVE-2026-79917 6.5 MEDIUM MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user
CVE-2026-79919 6.3 MEDIUM MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path c
CVE-2026-79918 6.3 MEDIUM MaxKB: Sandbox escape via unhooked fexecve
CVE-2026-77517 5.4 MEDIUM MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in
CVE-2026-77516 5.4 MEDIUM MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path
CVE-2026-77519 5.4 MEDIUM MaxKB: Expired application API keys remain usable on `/chat/api/mcp`
CVE-2026-77518 5.0 MEDIUM MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflo
CVE-2026-77522 4.3 MEDIUM MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fo
CVE-2026-77525 4.2 MEDIUM MaxKB: Management chat-record routes trust path application_id but load ChatRecord by glob

IV. Related Vulnerabilities

V. Comments for CVE-2026-77520

No comments yet


Leave a comment