CVE-2025-53928 is a critical Remote Command Execution (RCE) vulnerability affecting MaxKB, an open-source AI assistant, specifically in versions prior to 1.10.9-lts and 2.0.0. This flaw, located in the MCP call, allows unauthenticated attackers to execute arbitrary commands remotely with high impact on confidentiality, integrity, and availability, as indicated by its CVSS score of 9.8. While no public exploits (Metasploit, Nuclei, ExploitDB) or active exploitation have been identified, and community discussion is minimal, organizations using affected MaxKB versions should prioritize patching to mitigate this severe risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 1.10.9CPE matchmatch criteria | cpe:2.3:a:maxkb:maxkb:*:*:*:*:lts:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.