MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials wi
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 1Panel-dev | MaxKB | < 2.10.5-lts |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | MaxKB | < 2.10.5-lts | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77521 | 10.0 CRITICAL | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-77523 | 7.4 HIGH | MaxKB: Cross-workspace model parameter form write |
| CVE-2026-79917 | 6.5 MEDIUM | MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user |
| CVE-2026-79919 | 6.3 MEDIUM | MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path c |
| CVE-2026-79918 | 6.3 MEDIUM | MaxKB: Sandbox escape via unhooked fexecve |
| CVE-2026-77520 | 5.4 MEDIUM | MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to i |
| CVE-2026-77517 | 5.4 MEDIUM | MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in |
| CVE-2026-77516 | 5.4 MEDIUM | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path |
| CVE-2026-77519 | 5.4 MEDIUM | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` |
| CVE-2026-77518 | 5.0 MEDIUM | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflo |
| CVE-2026-77522 | 4.3 MEDIUM | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fo |
| CVE-2026-77525 | 4.2 MEDIUM | MaxKB: Management chat-record routes trust path application_id but load ChatRecord by glob |
No comments yet