Command Injection Vulnerability in MaxKB AI Assistant by 1Panel-dev
CVE-2026-77521

10CRITICAL

Key Information:

Vendor

1panel-dev

Status
Vendor
CVE Published:
21 September 2026

What is CVE-2026-77521?

MaxKB, an open-source AI assistant designed for enterprise use, is susceptible to a command injection vulnerability in versions prior to 2.10.5-lts. This flaw arises from the misuse of the SandboxShellBackend, which improperly exposes an execute shell tool and neglects to implement necessary security checks. As a result, untrusted chat inputs or other ingested content could lead to unauthorized command execution. Furthermore, deployments with MAXKB_SANDBOX disabled execute commands as the application user, intensifying the risk associated with unvetted content. Users are encouraged to upgrade to version 2.10.5-lts, where this vulnerability has been addressed, enhancing the application's security and integrity.

Affected Version(s)

MaxKB < 2.10.5-lts

References

CVSS V3.1

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Changed

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.