CVE-2026-39421 is a sandbox escape vulnerability affecting MaxKB, an open-source AI assistant platform, in versions 2.7.1 and below. The flaw resides in the ToolExecutor component and allows authenticated attackers to bypass the sandbox.so module by exploiting Python's ctypes library to execute raw system calls directly, ultimately achieving arbitrary code execution and potential container compromise. The vulnerability carries a CVSS score of 7.4 (HIGH) and requires network access with low attack complexity and low privileges, though it does require valid authentication. An authenticated attacker with workspace privileges can execute arbitrary code and exfiltrate data or compromise the container environment. The vulnerability specifically exploits a gap in sandbox protections where pkey_mprotect is not blocked despite restrictions on other memory protection calls like mprotect. There is no evidence of active exploitation in the wild, and the vulnerability is not listed on the KEV catalog. The EPSS score of 0.000860 indicates minimal current exploitation activity. The vulnerability has been patched in version 2.8.0, and users should prioritize upgrading to this version to mitigate the risk of unauthorized code execution within their MaxKB deployments.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.8.0CPE matchmatch criteria | cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.3 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.