MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, a normal user in the same workspace can obtain another user's application_id from the homepage application question-ranking endpoint when the published victim application has ranki
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 1Panel-dev | MaxKB | <= 2.10.2-lts |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | MaxKB | <= 2.10.2-lts | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77521 | 10.0 CRITICAL | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-79916 | 9.1 CRITICAL | MaxKB AWS Bedrock model credential injection leads to remote code execution |
| CVE-2026-77523 | 7.4 HIGH | MaxKB: Cross-workspace model parameter form write |
| CVE-2026-79917 | 6.5 MEDIUM | MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user |
| CVE-2026-79919 | 6.3 MEDIUM | MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path c |
| CVE-2026-79918 | 6.3 MEDIUM | MaxKB: Sandbox escape via unhooked fexecve |
| CVE-2026-77517 | 5.4 MEDIUM | MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in |
| CVE-2026-77516 | 5.4 MEDIUM | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path |
| CVE-2026-77519 | 5.4 MEDIUM | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` |
| CVE-2026-77518 | 5.0 MEDIUM | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflo |
| CVE-2026-77522 | 4.3 MEDIUM | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fo |
| CVE-2026-77525 | 4.2 MEDIUM | MaxKB: Management chat-record routes trust path application_id but load ChatRecord by glob |
No comments yet