Open-Source AI Assistant Vulnerability in MaxKB
CVE-2026-64870
5.3MEDIUM
What is CVE-2026-64870?
A vulnerability exists in MaxKB, an open-source AI assistant for enterprises, where certain parameters, specifically download_url and download_callback_url, can be exploited by authenticated users. This flaw allows these users to pose as legitimate requests to internal, loopback, link-local, or cloud metadata URLs. Although a fix has been developed on the v2 branch, it has not yet been released. This weakness raises significant security concerns regarding internal requests and unverified external URLs.
Affected Version(s)
MaxKB >= 2.0.0, <= 2.10.4-lts
