Maxkb

Vendor:

First CVE: Jan 2, 2025 · Active for 1 year

21
Total CVEs
More Total CVEs than 94% of tracked products
10.5
Avg CVEs / Year
Higher CVE frequency than 96% of tracked products
6.9
Avg CVSS
Higher Avg CVSS than 39% of tracked products
0.0%
KEV Rate
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact Maxkb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Jan 2, 2025
18 months ago
Most Recent CVE
Jun 25, 2026
29 days ago

CVE Severity & Scoring

Maxkb21 CVEs
All CVEs352,294 CVEs
LowMediumHighCritical
Attack Vector
Local2 (9.5%)
Network19 (90.5%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (90.5%)
High2 (9.5%)
Unknown0 (0.0%)
User Interaction
None16 (76.2%)
Unknown0 (0.0%)
Required5 (23.8%)
Privileges Required
Low16 (76.2%)
High3 (14.3%)
None2 (9.5%)
Unknown0 (0.0%)

Top CVEs

Signals from CVEs in this product scope (21 CVEs).

21 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under
Dec 11, 202510.030NONO
MaxKB before 2.10.0 contains a server-side request forgery vulnerability in tool creation and update endpoints that allows authenticated users to make arbitrary server requests by
Jun 25, 20266.429NONO
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSG_FASTOPEN flag. Th
Apr 14, 20267.429NONO
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool modul
Nov 13, 20258.828NONO
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts an
Jul 17, 20259.828NONO
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a sandbox escape vulnerability in the ToolExecutor component. By leveraging Python's ctypes li
Apr 14, 20267.425NONO
MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an incomplete sandbox protection mechanism allows an authenticated user with tool execution privil
Apr 14, 20267.425NONO
MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and othe
Dec 11, 20257.525NONO
MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/
Jun 3, 20258.824NONO
A vulnerability was found in 1Panel-dev MaxKB up to 1.10.7. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the component Knowledge
May 11, 20258.824NONO

Exploit Exposure

Signals from CVEs in this product scope (21 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

Signals from CVEs in this product scope (21 CVEs).

Media Mentions

Signals from CVEs in this product scope (21 CVEs).

Top CNAs Publishing CVEs For Maxkb

Top CWEs

Versions

No cataloged versions.