MaxKB

1Panel-dev · 47 CVEs

CVE-2026-79919
MEDIUM

MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(R…

Sep 21, 2026

CVE-2026-79918
MEDIUM

MaxKB: Sandbox escape via unhooked fexecve

Sep 21, 2026

CVE-2026-77517
MEDIUM

MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base

Sep 21, 2026

CVE-2026-77521
CRITICAL

MaxKB: Prompt-injectable agent can lead to command execution

Sep 21, 2026

CVE-2026-77522
MEDIUM

MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no inte…

Sep 21, 2026

CVE-2026-79917
MEDIUM

MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation

Sep 21, 2026

CVE-2026-77516
MEDIUM

MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path

Sep 21, 2026

CVE-2026-77523
HIGH

MaxKB: Cross-workspace model parameter form write

Sep 21, 2026

CVE-2026-77525
MEDIUM

MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id

Sep 21, 2026

CVE-2026-77518
MEDIUM

MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows

Sep 21, 2026

CVE-2026-79916
CRITICAL

MaxKB AWS Bedrock model credential injection leads to remote code execution

Sep 21, 2026

CVE-2026-77520
MEDIUM

MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's applicat…

Sep 21, 2026

CVE-2026-77519
MEDIUM

MaxKB: Expired application API keys remain usable on `/chat/api/mcp`

Sep 21, 2026

CVE-2026-64870
MEDIUM

MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation

Jul 30, 2026

CVE-2026-54149
HIGH

MaxKB MCP tool import validation bypass allows post-authentication remote code execution

Jul 10, 2026

CVE-2026-56779
MEDIUM

MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters

Jun 25, 2026

CVE-2026-42336
MEDIUM

MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch

May 26, 2026

CVE-2026-42337
MEDIUM

MaxKB: Broken Access Control in MaxKB OSS URL Fetch API

May 26, 2026

CVE-2026-44847
HIGH

MaxKB: Webhook Trigger Authentication Bypass

May 26, 2026

CVE-2026-45412
MEDIUM

MaxKB: Unauthenticated SSRF via Workflow Template Import

May 26, 2026

CVE-2026-45413
MEDIUM

MaxKB: Unsalted MD5 Password Hashing

May 26, 2026

CVE-2026-42335
MEDIUM

MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy

May 26, 2026

CVE-2026-39426
MEDIUM

MaxKB: Stored XSS via Unsanitized iframe_render Parsing

Apr 14, 2026

CVE-2026-39425
MEDIUM

MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering

Apr 14, 2026

CVE-2026-39419
LOW

MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing

Apr 14, 2026

Showing 1 to 25 of 47 CVEs