Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MaxKB — Vulnerabilities & Security Advisories 34

All 34 CVE vulnerabilities found in MaxKB, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive aggregation of Common Weakness Enumeration (CWE) vulnerabilities affecting MaxKB, an open-source knowledge base and RAG (Retrieval-Augmented Generation) application platform developed by Zilliz. The content covers a wide spectrum of security weaknesses, including cross-site scripting, insecure default configurations, and improper input validation, spanning vulnerability disclosures from the product's initial public release through current historical records. By centralizing this data, the page allows security professionals to efficiently track vendor advisories and monitor the patching lifecycle of MaxKB components. Users can gain a deeper understanding of specific weakness classes prevalent in the application and analyze the historical trend of security issues within this particular software ecosystem. This resource is designed to support threat modeling, risk assessment, and compliance auditing by providing a structured view of known defects without requiring external database queries. It serves as a reference point for developers and administrators to identify potential attack vectors and prioritize remediation efforts based on established industry standards. The aggregation includes details on severity, affected versions, and mitigation strategies where available, ensuring that stakeholders have access to actionable intelligence. This structured approach helps streamline the process of maintaining a secure deployment environment for MaxKB by highlighting persistent and critical vulnerabilities that require immediate attention or long-term architectural changes.

Vendor: 1Panel-dev

CVE IDTitleCVSSSeverityPublished
CVE-2026-64870 MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation CWE-918 5.3 Medium2026-07-30
CVE-2026-54149 MaxKB MCP tool import validation bypass allows post-authentication remote code execution CWE-78 8.8 High2026-07-10
CVE-2026-56779 MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters CWE-918 6.4 Medium2026-06-25
CVE-2026-42336 MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch CWE-367--2026-05-26
CVE-2026-42337 MaxKB: Broken Access Control in MaxKB OSS URL Fetch API CWE-862--2026-05-26
CVE-2026-44847 MaxKB: Webhook Trigger Authentication Bypass CWE-287 7.5 High2026-05-26
CVE-2026-45412 MaxKB: Unauthenticated SSRF via Workflow Template Import CWE-918--2026-05-26
CVE-2026-45413 MaxKB: Unsalted MD5 Password Hashing CWE-328--2026-05-26
CVE-2026-42335 MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy CWE-918--2026-05-26
CVE-2026-39426 MaxKB: Stored XSS via Unsanitized iframe_render Parsing CWE-79 5.4 -2026-04-14
CVE-2026-39425 MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering CWE-80 5.4 -2026-04-14
CVE-2026-39419 MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing CWE-74 3.1 Low2026-04-14
CVE-2026-39424 MaxKB has CSV Injection in its Application Chat Export Functionality CWE-1236 7.8 -2026-04-14
CVE-2026-39423 Stored XSS via Eval Injection in EchartsRander Component CWE-79 5.4 -2026-04-14
CVE-2026-39422 MaxKB has Stored XSS via ChatHeadersMiddleware CWE-79 5.4 -2026-04-14
CVE-2026-39421 MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotect CWE-693 6.3 Medium2026-04-14
CVE-2026-39420 MaxKB: Sandbox escape via LD_PRELOAD bypass CWE-693 6.3 Medium2026-04-14
CVE-2026-39418 MaxKB: SSRF via sandbox network hook bypass CWE-918 5.0 Medium2026-04-14
CVE-2026-39417 MaxKB: RCE via MCP stdio command injection in workflow engine CWE-78 4.6 Medium2026-04-14
CVE-2025-15632 1Panel-dev MaxKB MdPreview chat.ts cross site scripting CWE-79 3.5 Low2026-04-13
CVE-2026-6108 1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection CWE-78 6.3 Medium2026-04-12
CVE-2026-6107 1Panel-dev MaxKB ChatHeadersMiddleware chat_headers_middleware.py cross site scripting CWE-79 3.5 Low2026-04-12
CVE-2026-6106 1Panel-dev MaxKB Public Chat static_headers_middleware.py StaticHeadersMiddleware cross site scripting CWE-79 3.5 Low2026-04-11
CVE-2025-66446 MaxKB has a Python sandbox LD_PRELOAD bypass CWE-362 8.8 High2025-12-11
CVE-2025-66419 MaxKB vulnerable to privilege escalation through sandbox bypass CWE-362 8.8 High2025-12-11
CVE-2025-64703 MaxKB has Information Leak in sandbox CWE-200 6.3 Medium2025-11-13
CVE-2025-64511 MaxKB has SSRF in sandbox CWE-918 7.4 High2025-11-13
CVE-2025-10433 1Panel-dev MaxKB debug deserialization CWE-502 6.3 Medium2025-09-15
CVE-2025-53928 MaxKB has RCE in MCP call CWE-94 4.6 Medium2025-07-17
CVE-2025-53927 MaxKB sandbox bypass CWE-94 4.6 Medium2025-07-17

All 34 known CVE vulnerabilities affecting MaxKB with full Chinese analysis, references, and POCs where available.