MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get with verify=False and with
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 1Panel-dev | MaxKB | <= 2.10.3-lts |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | MaxKB | <= 2.10.3-lts | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77521 | 10.0 CRITICAL | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-79916 | 9.1 CRITICAL | MaxKB AWS Bedrock model credential injection leads to remote code execution |
| CVE-2026-77523 | 7.4 HIGH | MaxKB: Cross-workspace model parameter form write |
| CVE-2026-79917 | 6.5 MEDIUM | MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user |
| CVE-2026-79919 | 6.3 MEDIUM | MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path c |
| CVE-2026-79918 | 6.3 MEDIUM | MaxKB: Sandbox escape via unhooked fexecve |
| CVE-2026-77520 | 5.4 MEDIUM | MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to i |
| CVE-2026-77517 | 5.4 MEDIUM | MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in |
| CVE-2026-77516 | 5.4 MEDIUM | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path |
| CVE-2026-77519 | 5.4 MEDIUM | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` |
| CVE-2026-77518 | 5.0 MEDIUM | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflo |
| CVE-2026-77525 | 4.2 MEDIUM | MaxKB: Management chat-record routes trust path application_id but load ChatRecord by glob |
No comments yet