Maxkb

Maxkb

20 Schwachstellen gefunden.

Hinweis: Diese Liste kann unvollständig sein. Daten werden ohne Gewähr im Ursprungsformat bereitgestellt.
  • EPSS 0.05%
  • Veröffentlicht 14.04.2026 01:25:10
  • Zuletzt bearbeitet 20.04.2026 17:31:20

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom <iframe_render> tags from LLM responses or Application...

  • EPSS 0.07%
  • Veröffentlicht 14.04.2026 01:18:42
  • Zuletzt bearbeitet 20.04.2026 17:31:48

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability that allows authenticated users to inject arbitrary HTML and JavaScript into the Application prologue (Opening Rem...

  • EPSS 0.05%
  • Veröffentlicht 14.04.2026 01:03:40
  • Zuletzt bearbeitet 20.04.2026 17:32:17

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandbox result validation and spoof tool execution results by exploiting Python frame introspection to read the wrapper's UUID from its...

  • EPSS 0.06%
  • Veröffentlicht 14.04.2026 00:56:56
  • Zuletzt bearbeitet 20.04.2026 17:34:19

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, the chat export feature is vulnerable to Improper Neutralization of Formula Elements in a CSV File. When an administrator exports the application chat history to an Exc...

  • EPSS 0.04%
  • Veröffentlicht 14.04.2026 00:28:47
  • Zuletzt bearbeitet 20.04.2026 17:34:28

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting with the AI chat interface to execute arbitrary JavaScr...

Exploit
  • EPSS 0.04%
  • Veröffentlicht 14.04.2026 00:22:50
  • Zuletzt bearbeitet 20.04.2026 17:34:36

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability through the application name or icon fields when creating an application. When a victim visits the public chat int...

  • EPSS 0.07%
  • Veröffentlicht 14.04.2026 00:17:10
  • Zuletzt bearbeitet 20.04.2026 17:35:05

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. By leveraging Python's ctypes library to execute raw system calls, an authenticated attacker with work...

  • EPSS 0.15%
  • Veröffentlicht 14.04.2026 00:13:01
  • Zuletzt bearbeitet 20.04.2026 17:35:22

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mechanism allows an authenticated user with tool execution privileges to escape the LD_PRELOAD-based sandbox. By env command the attack...

  • EPSS 0.03%
  • Veröffentlicht 14.04.2026 00:08:50
  • Zuletzt bearbeitet 20.04.2026 17:36:04

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSG_FASTOPEN flag. This allows authenticated user with tool-editing permissions to reach in...

  • EPSS 0.06%
  • Veröffentlicht 14.04.2026 00:03:16
  • Zuletzt bearbeitet 20.04.2026 17:36:38

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execution vulnerability still exists in the MCP node of the workflow engine. MaxKB only restricts the refe...