Skip to content
Noroxi

maxkb records

20 published records for vendor maxkb.

All records

20 records
  • MaxKB vulnerable to privilege escalation through sandbox bypass

    CriticalCVSS 10.0No exploitEPSS 0%

    maxkb · maxkbDec 11, 2025

  • MaxKB has RCE in MCP call

    CriticalCVSS 9.8No exploitEPSS 0%

    maxkb · maxkbJul 17, 2025

  • MaxKB has SSRF in sandbox

    HighCVSS 8.8No exploitEPSS 0%

    maxkb · maxkbNov 13, 2025

  • MaxKB has a Python sandbox LD_PRELOAD bypass

    HighCVSS 7.5No exploitEPSS 0%

    maxkb · maxkbDec 11, 2025

  • MaxKB: Sandbox escape via LD_PRELOAD bypass

    HighCVSS 7.4No exploitEPSS 1%

    maxkb · maxkbApr 13, 2026

  • MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotect

    HighCVSS 7.4No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • MaxKB: SSRF via sandbox network hook bypass

    HighCVSS 7.4No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • MaxKB RCE vulnerability in function library

    HighCVSS 7.2No exploitEPSS 1%

    maxkb · maxkbJan 2, 2025

  • MaxKB has a reverse shell vulnerability in function library

    HighCVSS 7.2No exploitEPSS 0%

    maxkb · maxkbApr 10, 2025

  • MaxKB has Stored XSS via ChatHeadersMiddleware

    MediumCVSS 6.9No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • Stored XSS via Eval Injection in EchartsRander Component

    MediumCVSS 6.9No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • MaxKB has Information Leak in sandbox

    MediumCVSS 6.5No exploitEPSS 0%

    maxkb · maxkbNov 13, 2025

  • MaxKB sandbox bypass

    MediumCVSS 6.3No exploitEPSS 0%

    maxkb · maxkbJul 17, 2025

  • MaxKB Python Sandbox Bypass in Function Library

    MediumCVSS 5.8No exploitEPSS 0%

    maxkb · maxkbJun 3, 2025

  • MaxKB: RCE via MCP stdio command injection in workflow engine

    MediumCVSS 5.5No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • MaxKB has CSV Injection in its Application Chat Export Functionality

    MediumCVSS 5.3No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • CVE-2025-4546
    20Monitor

    1Panel-dev MaxKB Knowledge Base Module csv injection

    MediumCVSS 5.1No exploitEPSS 1%

    maxkb · maxkbMay 11, 2025

  • MaxKB: Stored XSS via Unsanitized html_rander Tags in Markdown Rendering

    MediumCVSS 5.1No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • MaxKB: Stored XSS via Unsanitized iframe_render Parsing

    MediumCVSS 5.1No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026

  • MaxKB: Sandbox Result Validation Bypass via Tool Output Spoofing

    LowCVSS 3.1No exploitEPSS 0%

    maxkb · maxkbApr 13, 2026