Maxkb is a modestly represented vendor focused on a single knowledge-base and document-management product that has drawn a meaningful share of critical-severity disclosures. The vulnerability pattern recurs across input-handling and code-execution boundaries: code injection, cross-site scripting, OS command injection, and race conditions reflect the architectural risk of a web-facing application that processes and executes user-supplied or templated content. Defenders deploying this product should prioritize input validation, output encoding, and access control hardening; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Maxkb over time
Signals from CVEs in this vendor scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66419CRITICAL MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under | Dec 11, 2025 | 10.0 | 30 | NO | NO |
CVE-2026-56779MEDIUM MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by | Jun 25, 2026 | 6.4 | 29 | NO | NO |
CVE-2026-39418HIGH MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSG_FASTOPEN flag. Th | Apr 14, 2026 | 7.4 | 29 | NO | NO |
CVE-2025-64511HIGH MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool modul | Nov 13, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-53928CRITICAL MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts an | Jul 17, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-39421HIGH MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. By leveraging Python's ctypes li | Apr 14, 2026 | 7.4 | 25 | NO | NO |
CVE-2026-39420HIGH MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mechanism allows an authenticated user with tool execution privil | Apr 14, 2026 | 7.4 | 25 | NO | NO |
CVE-2025-66446HIGH MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and othe | Dec 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-48950HIGH MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/ | Jun 3, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-4546HIGH A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Knowledge | May 11, 2025 | 8.8 | 24 | NO | NO |
Signals from CVEs in this vendor scope (21 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Maxkb.
Media articles that mention a CVE ID that affects a product developed by Maxkb — matched by CVE ID, not by vendor name.