Maxkb
Vendor:
First CVE: Jan 2, 2025 · Active for 1 year
21
Total CVEs
More Total CVEs than 94% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%
Trends Over Time
The number and severity of CVEs published that impact Maxkb over time
Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 2025
18 months ago
Most Recent CVE
Jun 25, 2026
29 days ago
CVE Severity & Scoring
Maxkb21 CVEs
43%
43%
10%
All CVEs352,294 CVEs
45%
40%
11%
LowMediumHighCritical
Attack Vector
Local2 (9.5%)
Network19 (90.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (90.5%)
High2 (9.5%)
Unknown0 (0.0%)
User Interaction
None16 (76.2%)
Unknown0 (0.0%)
Required5 (23.8%)
Privileges Required
Low16 (76.2%)
High3 (14.3%)
None2 (9.5%)
Unknown0 (0.0%)
Top CVEs
Signals from CVEs in this product scope (21 CVEs).
21 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-66419CRITICAL MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under | Dec 11, 2025 | 10.0 | 30 | NO | NO |
CVE-2026-56779MEDIUM MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by | Jun 25, 2026 | 6.4 | 29 | NO | NO |
CVE-2026-39418HIGH MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSG_FASTOPEN flag. Th | Apr 14, 2026 | 7.4 | 29 | NO | NO |
CVE-2025-64511HIGH MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool modul | Nov 13, 2025 | 8.8 | 28 | NO | NO |
CVE-2025-53928CRITICAL MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts an | Jul 17, 2025 | 9.8 | 28 | NO | NO |
CVE-2026-39421HIGH MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. By leveraging Python's ctypes li | Apr 14, 2026 | 7.4 | 25 | NO | NO |
CVE-2026-39420HIGH MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mechanism allows an authenticated user with tool execution privil | Apr 14, 2026 | 7.4 | 25 | NO | NO |
CVE-2025-66446HIGH MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and othe | Dec 11, 2025 | 7.5 | 25 | NO | NO |
CVE-2025-48950HIGH MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/ | Jun 3, 2025 | 8.8 | 24 | NO | NO |
CVE-2025-4546HIGH A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Knowledge | May 11, 2025 | 8.8 | 24 | NO | NO |
Exploit Exposure
Signals from CVEs in this product scope (21 CVEs).
CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%
Social Chatter
Signals from CVEs in this product scope (21 CVEs).
Media Mentions
Signals from CVEs in this product scope (21 CVEs).
Top CNAs Publishing CVEs For Maxkb
Top CWEs
Versions
No cataloged versions.