Command Injection Vulnerability in MaxKB AI Assistant by 1Panel-dev
CVE-2026-77521
10CRITICAL
What is CVE-2026-77521?
MaxKB, an open-source AI assistant designed for enterprise use, is susceptible to a command injection vulnerability in versions prior to 2.10.5-lts. This flaw arises from the misuse of the SandboxShellBackend, which improperly exposes an execute shell tool and neglects to implement necessary security checks. As a result, untrusted chat inputs or other ingested content could lead to unauthorized command execution. Furthermore, deployments with MAXKB_SANDBOX disabled execute commands as the application user, intensifying the risk associated with unvetted content. Users are encouraged to upgrade to version 2.10.5-lts, where this vulnerability has been addressed, enhancing the application's security and integrity.
Affected Version(s)
MaxKB < 2.10.5-lts
