Vulnerabilities
Vulnerable Software
Maxkb:  >> Maxkb  >> 1.10.8  Security Vulnerabilities
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use the `shutil.copy2` method in Python to copy the command they want to execute to the executable directory. This bypasses directory restrictions and reverse shell. Version 2.0.0 fixes the issue.
CVSS Score
4.6
EPSS Score
0.0
Published
2025-07-17
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.
CVSS Score
4.6
EPSS Score
0.005
Published
2025-07-17


Contact Us

Shodan ® - All rights reserved