Vulnerabilities
Vulnerable Software
Maxkb:  >> Maxkb  >> 2.0.1  Security Vulnerabilities
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.
CVSS Score
8.8
EPSS Score
0.0
Published
2025-12-11
MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0.
CVSS Score
8.8
EPSS Score
0.0
Published
2025-12-11
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool module, although the process runs in a sandbox. Version 2.3.1 fixes the issue.
CVSS Score
7.4
EPSS Score
0.001
Published
2025-11-13
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module, although the process run in sandbox. Version 2.3.1 fixes the issue.
CVSS Score
6.3
EPSS Score
0.0
Published
2025-11-13


Contact Us

Shodan ® - All rights reserved