MaxKB
1Panel-dev · 47 CVEs
MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(R…
Sep 21, 2026
MaxKB: Sandbox escape via unhooked fexecve
Sep 21, 2026
MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base
Sep 21, 2026
MaxKB: Prompt-injectable agent can lead to command execution
Sep 21, 2026
MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no inte…
Sep 21, 2026
MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation
Sep 21, 2026
MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path
Sep 21, 2026
MaxKB: Cross-workspace model parameter form write
Sep 21, 2026
MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id
Sep 21, 2026
MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows
Sep 21, 2026
MaxKB AWS Bedrock model credential injection leads to remote code execution
Sep 21, 2026
MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's applicat…
Sep 21, 2026
MaxKB: Expired application API keys remain usable on `/chat/api/mcp`
Sep 21, 2026
MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation
Jul 30, 2026
MaxKB MCP tool import validation bypass allows post-authentication remote code execution
Jul 10, 2026
MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters
Jun 25, 2026
MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch
May 26, 2026
MaxKB: Broken Access Control in MaxKB OSS URL Fetch API
May 26, 2026
MaxKB: Webhook Trigger Authentication Bypass
May 26, 2026
MaxKB: Unauthenticated SSRF via Workflow Template Import
May 26, 2026
MaxKB: Unsalted MD5 Password Hashing
May 26, 2026
MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy
May 26, 2026
MaxKB: Stored XSS via Unsanitized iframe_render Parsing
Apr 14, 2026
MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering
Apr 14, 2026
MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing
Apr 14, 2026
| CVE ID | Description | Severity | EPSS | Published |
|---|---|---|---|---|
| CVE-2026-79919 | MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT) | MEDIUM | 0.39% | Sep 21, 2026 |
| CVE-2026-79918 | MaxKB: Sandbox escape via unhooked fexecve | MEDIUM | 0.36% | Sep 21, 2026 |
| CVE-2026-77517 | MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base | MEDIUM | 0.23% | Sep 21, 2026 |
| CVE-2026-77521 | MaxKB: Prompt-injectable agent can lead to command execution | CRITICAL | 1.05% | Sep 21, 2026 |
| CVE-2026-77522 | MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind) | MEDIUM | 0.30% | Sep 21, 2026 |
| CVE-2026-79917 | MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation | MEDIUM | 0.27% | Sep 21, 2026 |
| CVE-2026-77516 | MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path | MEDIUM | 0.24% | Sep 21, 2026 |
| CVE-2026-77523 | MaxKB: Cross-workspace model parameter form write | HIGH | 0.26% | Sep 21, 2026 |
| CVE-2026-77525 | MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id | MEDIUM | 0.19% | Sep 21, 2026 |
| CVE-2026-77518 | MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows | MEDIUM | 0.27% | Sep 21, 2026 |
| CVE-2026-79916 | MaxKB AWS Bedrock model credential injection leads to remote code execution | CRITICAL | 0.45% | Sep 21, 2026 |
| CVE-2026-77520 | MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application | MEDIUM | 0.23% | Sep 21, 2026 |
| CVE-2026-77519 | MaxKB: Expired application API keys remain usable on `/chat/api/mcp` | MEDIUM | 0.24% | Sep 21, 2026 |
| CVE-2026-64870 | MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation | MEDIUM | 0.36% | Jul 30, 2026 |
| CVE-2026-54149 | MaxKB MCP tool import validation bypass allows post-authentication remote code execution | HIGH | 0.55% | Jul 10, 2026 |
| CVE-2026-56779 | MaxKB < 2.10.0 - Server-Side Request Forgery via downloadCallbackUrl and download_url Parameters | MEDIUM | 0.29% | Jun 25, 2026 |
| CVE-2026-42336 | MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch | MEDIUM | 0.27% | May 26, 2026 |
| CVE-2026-42337 | MaxKB: Broken Access Control in MaxKB OSS URL Fetch API | MEDIUM | 0.35% | May 26, 2026 |
| CVE-2026-44847 | MaxKB: Webhook Trigger Authentication Bypass | HIGH | 0.46% | May 26, 2026 |
| CVE-2026-45412 | MaxKB: Unauthenticated SSRF via Workflow Template Import | MEDIUM | 0.35% | May 26, 2026 |
| CVE-2026-45413 | MaxKB: Unsalted MD5 Password Hashing | MEDIUM | 0.11% | May 26, 2026 |
| CVE-2026-42335 | MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy | MEDIUM | 0.37% | May 26, 2026 |
| CVE-2026-39426 | MaxKB: Stored XSS via Unsanitized iframe_render Parsing | MEDIUM | 0.25% | Apr 14, 2026 |
| CVE-2026-39425 | MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering | MEDIUM | 0.28% | Apr 14, 2026 |
| CVE-2026-39419 | MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing | LOW | 0.35% | Apr 14, 2026 |
Showing 1 to 25 of 47 CVEs