Remote Command Execution Vulnerability in MaxKB AI Assistant by 1Panel
CVE-2025-53928

4.6MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
17 July 2025

What is CVE-2025-53928?

MaxKB, an open-source AI assistant developed by 1Panel for enterprise environments, is impacted by a Remote Command Execution vulnerability in its MCP call feature. This flaw allows attackers to execute arbitrary commands on the server. Users are advised to upgrade to versions 1.10.9-lts or 2.0.0, which contain necessary security patches to mitigate this risk. For further details, refer to the advisories and release notes provided by 1Panel.

Affected Version(s)

MaxKB < 2.0.0 < 2.0.0

MaxKB < 1.10.9-lts < 1.10.9-lts

References

CVSS V3.1

Score:
4.6
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
High
Privileges Required:
Low
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-53928 : Remote Command Execution Vulnerability in MaxKB AI Assistant by 1Panel