Code Execution Vulnerability in MaxKB AI Assistant by 1Panel
CVE-2026-79919
6.3MEDIUM
What is CVE-2026-79919?
MaxKB, an open-source AI assistant for enterprises, has a vulnerability that allows authenticated users to bypass the sandbox environment. This issue arises from a flaw in function-library code that permits the invocation of ctypes.CDLL through an importlib callback, enabling unauthorized file access, process execution, or network interaction as the sandbox user. The vulnerability is addressed in version 2.10.6-lts, urging users to update promptly to ensure security.
Affected Version(s)
MaxKB < 2.10.6-lts
