Open-Source AI Assistant Vulnerability in MaxKB by 1Panel
CVE-2025-64703

6.3MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
13 November 2025

What is CVE-2025-64703?

In MaxKB, an open-source AI assistant developed by 1Panel, a security issue exists in versions below 2.3.1 that allows users to exploit Python code within the tool module to access sensitive information. Although the execution occurs in a sandboxed environment, the vulnerability poses significant risks to enterprise data integrity and confidentiality. The issue has been rectified in version 2.3.1, emphasizing the importance of updating to maintain security.

Affected Version(s)

MaxKB < 2.3.1

References

CVSS V3.1

Score:
6.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
Low
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-64703 : Open-Source AI Assistant Vulnerability in MaxKB by 1Panel