Server-Side Request Forgery Vulnerability in MaxKB AI Assistant
CVE-2026-42335

6.3MEDIUM

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
26 May 2026

What is CVE-2026-42335?

MaxKB, an open-source AI assistant for enterprise, is susceptible to a server-side request forgery (SSRF) vulnerability in the OSS file service URL fetch endpoint. Due to inconsistent URL parsing between the validation function and the HTTP client, attackers may exploit this vulnerability to gain unauthorized access to internal network services. The issue was addressed in version 2.8.1, providing necessary protection against such unauthorized access.

Affected Version(s)

MaxKB < 2.8.1

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.