CVE-2025-53928: CWE-94: Improper Control of Generation of Code ('Code Injection') in 1Panel-dev MaxKB
Severity: mediumType: vulnerabilityCVE-2025-53928
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.
CVE-2025-53928: CWE-94: Improper Control of Generation of Code ('Code Injection') in 1Panel-dev MaxKB
Medium
Published: Thu Jul 17 2025 (07/17/2025, 13:56:02 UTC)
Source: CVE Database V5
Vendor/Project: 1Panel-dev
Product: MaxKB
Description
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- GitHub_M
- Date Reserved
- 2025-07-14T17:23:35.259Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 68790228a83201eaace61c00
Added to database: 7/17/2025, 2:01:12 PM
Last updated: 7/17/2025, 2:01:12 PM
Views: 1
Related Threats
CVE-2025-53927: CWE-94: Improper Control of Generation of Code ('Code Injection') in 1Panel-dev MaxKB
MediumVulnerabilityThu Jul 17 2025
CVE-2025-53909: CWE-1336: Improper Neutralization of Special Elements Used in a Template Engine in mailcow mailcow-dockerized
CriticalVulnerabilityThu Jul 17 2025
CVE-2025-51630: n/a
UnknownVulnerabilityThu Jul 17 2025
CVE-2025-40924: CWE-340 Generation of Predictable Numbers or Identifiers in HAARG Catalyst::Plugin::Session
HighVulnerabilityThu Jul 17 2025
CVE-2025-5346: CWE-926 Improper Export of Android Application Components in Bluebird kr.co.bluebird.android.bbsettings
MediumVulnerabilityThu Jul 17 2025
Actions
Please log in to the Console to use AI analysis features.
Need enhanced features?
Contact root@offseq.com for Pro access with improved analysis and higher rate limits.