Maxkb

Maxkb

10 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.04%
  • Veröffentlicht 11.12.2025 21:47:22
  • Zuletzt bearbeitet 15.12.2025 17:58:54

MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This ...

  • EPSS 0.05%
  • Veröffentlicht 11.12.2025 21:39:15
  • Zuletzt bearbeitet 15.12.2025 18:05:09

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.

  • EPSS 0.05%
  • Veröffentlicht 13.11.2025 15:52:44
  • Zuletzt bearbeitet 04.12.2025 14:55:30

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module, although the process run in sandbox. Version 2.3.1 fixes the issue.

  • EPSS 0.06%
  • Veröffentlicht 13.11.2025 15:51:53
  • Zuletzt bearbeitet 04.12.2025 15:13:37

MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool module, although the process runs in a sandbox. Version 2.3.1 fixes the iss...

Exploit
  • EPSS 0.59%
  • Veröffentlicht 17.07.2025 13:56:02
  • Zuletzt bearbeitet 02.08.2025 01:35:53

MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.

Exploit
  • EPSS 0.03%
  • Veröffentlicht 17.07.2025 13:50:18
  • Zuletzt bearbeitet 02.08.2025 01:34:28

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use the `shutil....

Exploit
  • EPSS 0.15%
  • Veröffentlicht 03.06.2025 18:16:09
  • Zuletzt bearbeitet 06.08.2025 19:13:50

MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/bin,/usr/bin`, etc. Therefore, attackers can exploit some files with e...

Exploit
  • EPSS 0.31%
  • Veröffentlicht 11.05.2025 20:00:06
  • Zuletzt bearbeitet 08.07.2025 17:08:09

A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Knowledge Base Module. The manipulation leads to csv injection. The attack can b...

  • EPSS 0.23%
  • Veröffentlicht 10.04.2025 13:07:12
  • Zuletzt bearbeitet 01.08.2025 21:10:16

MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability ...

Exploit
  • EPSS 3.1%
  • Veröffentlicht 02.01.2025 15:15:24
  • Zuletzt bearbeitet 01.08.2025 20:15:27

MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). Prior to version 1.9.0, a remote command execution vulnerability exists i...