Injection Vulnerability in MaxKB Open Source AI Assistant
CVE-2026-79916
9.1CRITICAL
What is CVE-2026-79916?
MaxKB, an open-source AI assistant for enterprises, is susceptible to an injection vulnerability affecting its AWS credentials management. Prior to version 2.10.5-lts, authenticated users could inject control characters into the AWS access_key_id and secret_access_key fields. This flaw permits an attacker to manipulate the AWS credentials at /root/.aws/credentials, enabling them to create a new AWS profile with a credential_process that can execute arbitrary commands with root privileges during model validation requests. This vulnerability has been addressed in the recently released version 2.10.5-lts.
Affected Version(s)
MaxKB < 2.10.5-lts
