Sandbox Bypass Vulnerability in MaxKB AI Assistant by 1Panel
CVE-2025-64511
7.4HIGH
What is CVE-2025-64511?
A vulnerability exists in MaxKB, an open-source AI assistant for enterprises, where prior versions (before 2.3.1) permit unauthorized access to internal network services, such as databases. This flaw enables users to execute Python code within the tool module, even in a sandboxed environment, potentially exposing sensitive data. Users are advised to update to version 2.3.1 or later to mitigate this risk.
Affected Version(s)
MaxKB < 2.3.1
