Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/1panel-dev/MaxKB

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-79919 is a protection mechanism failure vulnerability in MaxKB, an open-source AI assistant for enterprise. Versions prior to 2.10.6-lts allow an authenticated workspace member to bypass the LD_PRELOAD sandbox syscall blacklist by exploiting a flaw in how ctypes.CDLL is invoked from a MetaPathFinder callback. This enables unauthorized read/write file access, process execution, and network access as the sandbox user. The issue is fixed in version 2.10.6-lts.

Join the discussion

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.

Join the discussion

CVE-2026-77517 is an authorization bypass vulnerability in 1Panel-dev MaxKB versions 2.0.0 through 2.10.2-lts. The issue arises because the document and paragraph operate routes authorize only the knowledge_id in the request path but do not verify that the document or paragraph actually belongs to that knowledge base. This allows a user with access to a known document or paragraph UUID to read or modify content in another user's knowledge base by using an attacker-controlled knowledge base path. No fixed version is currently available.

Join the discussion

CVE-2026-77521 is a critical OS command injection vulnerability in MaxKB, an open-source AI assistant for enterprise. Versions prior to 2.10.5-lts allow untrusted input to execute shell commands without human approval due to improper sandboxing and command execution controls. This can lead to full system compromise by executing arbitrary commands as the application user. The issue is fixed in version 2.10.5-lts.

Join the discussion

MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get with verify=False and without restricting schemes, loopback, link-local, private, or reserved addresses. The response body is converted into imported document content, allowing a low-privileged user to read cloud metadata or internal HTTP services through the MaxKB server. No fixed version is available as of this review.

Join the discussion

CVE-2026-79917 is an improper authorization vulnerability in MaxKB versions 2.7.0 through 2.10.4-lts. The flaw allows an attacker with any valid chat token and knowledge of a victim's chat ID to create a public share link for the victim's conversation without verifying ownership. This also enables unauthorized public access to associated files with no way to revoke access. No patch or fix is currently available.

Join the discussion

MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.9.2, a lowest-role workspace member denied access to a tool by WorkspaceUserResourcePermission can still bind its identifier through tool_ids, skill_tool_ids, or mcp_tool_ids and execute it through the agent or workflow dispatch path. The dispatch path does not reapply the per-tool grant enforced by dedicated tool routes, and tool execution decrypts server-side init_params, allowing the caller to receive credentials carried by the denied tool. No fixed version is available as of this review.

Join the discussion

CVE-2026-77523 is an authorization bypass vulnerability in MaxKB, an open-source AI assistant for enterprise. In versions 2.10.3-lts and earlier, the model parameter form route authorizes access based on workspace path, but the underlying ModelSerializer.ModelParams loads and saves models by ID alone without verifying workspace ownership. This allows an authenticated user with read permission in an attacker-controlled workspace to access or modify model parameters in other workspaces by supplying a victim's model ID. No patch or fixed version is currently available.

Join the discussion

MaxKB is an open-source AI assistant for enterprise. In 2.10.2-lts and earlier, management chat-record routes authorize the path application_id but load records using global chat_id and chat_record_id values without confirming that the chat belongs to the authorized application. A normal user in the same workspace who knows the chat_id of a persisted non-debug record for a victim's published application can place it under a separate attacker-owned application path to read victim chat records. An attacker with an owned knowledge base and document can also use add_knowledge to copy victim answers while updating the victim record's improve_paragraph_id_list. No fixed version is available as of this review.

Join the discussion

CVE-2026-77518 is a missing authorization vulnerability in MaxKB, an open-source AI assistant for enterprise. In versions 2.10.2-lts and earlier, a normal workspace user can access hidden tools of other users within the same workspace by knowing the tool's MCP tool_id. This occurs because the tool-detail route lacks per-resource authorization checks, unlike the list route. The exposed tool details include Tool.code, which may contain sensitive MCP server configuration and headers. Additionally, an attacker who can create or edit workflows can misuse another user's MCP configuration by referencing their tool_id in a workflow node without permission verification. No fix is currently available for this issue.

Join the discussion

Showing 1 to 10 of 40 results

Filters:Package: pkg:github/1panel-dev/MaxKB
Page 1 of 4
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses