Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

MaxKB — Vulnerabilities & Security Advisories 47

All 47 CVE vulnerabilities found in MaxKB, with AI-generated Chinese analysis, references, and POCs.

This section aggregates known security weaknesses for the open-source knowledge base platform MaxKB, focusing on specific vulnerability classes and their remediation status. The collection covers historical and current security advisories published by the vendor or third-party researchers, spanning from the product's initial release through the latest security updates. Readers can use this page to track the vendor's disclosure patterns, analyze recurring weakness types, and review the complete vulnerability history associated with this software.

Vendor: 1Panel-dev

CVE ID Title CVSS Severity Published
CVE-2026-79919 MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT) CWE-693 6.3 Medium 2026-09-21
CVE-2026-79918 MaxKB: Sandbox escape via unhooked fexecve CWE-693 6.3 Medium 2026-09-21
CVE-2026-77517 MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base CWE-639 5.4 Medium 2026-09-21
CVE-2026-77521 MaxKB: Prompt-injectable agent can lead to command execution CWE-78 10.0 Critical 2026-09-21
CVE-2026-77522 MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind) CWE-918 4.3 Medium 2026-09-21
CVE-2026-79917 MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation CWE-285 6.5 Medium 2026-09-21
CVE-2026-77516 MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path CWE-639 5.4 Medium 2026-09-21
CVE-2026-77523 MaxKB: Cross-workspace model parameter form write CWE-639 7.4 High 2026-09-21
CVE-2026-77525 MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id CWE-862 4.2 Medium 2026-09-21
CVE-2026-77518 MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows CWE-862 5.0 Medium 2026-09-21
CVE-2026-79916 MaxKB AWS Bedrock model credential injection leads to remote code execution CWE-78 9.1 Critical 2026-09-21
CVE-2026-77520 MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application CWE-862 5.4 Medium 2026-09-21
CVE-2026-77519 MaxKB: Expired application API keys remain usable on `/chat/api/mcp` CWE-613 5.4 Medium 2026-09-21
CVE-2026-64870 MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation CWE-918 5.3 Medium 2026-07-30
CVE-2026-54149 MaxKB MCP tool import validation bypass allows post-authentication remote code execution CWE-78 8.8 High 2026-07-10
CVE-2026-56779 MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters CWE-918 6.4 Medium 2026-06-25
CVE-2026-42336 MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch CWE-367 - - 2026-05-26
CVE-2026-42337 MaxKB: Broken Access Control in MaxKB OSS URL Fetch API CWE-862 - - 2026-05-26
CVE-2026-44847 MaxKB: Webhook Trigger Authentication Bypass CWE-287 7.5 High 2026-05-26
CVE-2026-45412 MaxKB: Unauthenticated SSRF via Workflow Template Import CWE-918 - - 2026-05-26
CVE-2026-45413 MaxKB: Unsalted MD5 Password Hashing CWE-328 - - 2026-05-26
CVE-2026-42335 MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy CWE-918 - - 2026-05-26
CVE-2026-39426 MaxKB: Stored XSS via Unsanitized iframe_render Parsing CWE-79 5.4 - 2026-04-14
CVE-2026-39425 MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering CWE-80 5.4 - 2026-04-14
CVE-2026-39419 MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing CWE-74 3.1 Low 2026-04-14
CVE-2026-39424 MaxKB has CSV Injection in its Application Chat Export Functionality CWE-1236 7.8 - 2026-04-14
CVE-2026-39423 Stored XSS via Eval Injection in EchartsRander Component CWE-79 5.4 - 2026-04-14
CVE-2026-39422 MaxKB has Stored XSS via ChatHeadersMiddleware CWE-79 5.4 - 2026-04-14
CVE-2026-39421 MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotect CWE-693 6.3 Medium 2026-04-14
CVE-2026-39420 MaxKB: Sandbox escape via LD_PRELOAD bypass CWE-693 6.3 Medium 2026-04-14

All 47 known CVE vulnerabilities affecting MaxKB with full Chinese analysis, references, and POCs where available.