MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_user_id or to the appl
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 1Panel-dev | MaxKB | >= 2.7.0, <= 2.10.4-lts |
affected |
Shenlong is analyzing...
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| 1Panel-dev | MaxKB | >= 2.7.0, <= 2.10.4-lts | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-77521 | 10.0 CRITICAL | MaxKB: Prompt-injectable agent can lead to command execution |
| CVE-2026-79916 | 9.1 CRITICAL | MaxKB AWS Bedrock model credential injection leads to remote code execution |
| CVE-2026-77523 | 7.4 HIGH | MaxKB: Cross-workspace model parameter form write |
| CVE-2026-79919 | 6.3 MEDIUM | MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path c |
| CVE-2026-79918 | 6.3 MEDIUM | MaxKB: Sandbox escape via unhooked fexecve |
| CVE-2026-77520 | 5.4 MEDIUM | MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to i |
| CVE-2026-77517 | 5.4 MEDIUM | MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in |
| CVE-2026-77516 | 5.4 MEDIUM | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path |
| CVE-2026-77519 | 5.4 MEDIUM | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` |
| CVE-2026-77518 | 5.0 MEDIUM | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflo |
| CVE-2026-77522 | 4.3 MEDIUM | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fo |
| CVE-2026-77525 | 4.2 MEDIUM | MaxKB: Management chat-record routes trust path application_id but load ChatRecord by glob |
No comments yet