Server-Side Request Forgery in MaxKB AI Assistant by 1Panel
CVE-2026-45412
6.3MEDIUM
What is CVE-2026-45412?
MaxKB, an open-source AI assistant developed by 1Panel, is susceptible to a Server-Side Request Forgery (SSRF) vulnerability due to insufficient input validation. This issue allows authenticated users to input arbitrary URLs through the 'work_flow_template.downloadUrl' field, which the server fetches without proper validation or filtering of internal IP addresses. This vulnerability poses a risk of exposing sensitive internal resources and was addressed in version 2.9.1.
Affected Version(s)
MaxKB < 2.9.1
