CVE Explorer
CVE-2026-39417
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execution vulnerability still exists in the MCP node of the workflow engine. MaxKB only restricts the referencing code path (loading MCP config from the database). The else branch, responsible for loading mcp_servers directly from user-supplied JSON remains completely unpatched. Since mcp_source is an optional field (required=False), an attacker can simp
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
cwe · 2 assertions
{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/problemTypes/1/descriptions/0
Affected products and versions
1 source assertion{"product":"MaxKB","vendor":"1Panel-dev","versions":[{"status":"affected","version":"< 2.8.0"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"HIGH","attackVector":"NETWORK","availabilityImpact":"LOW","baseScore":4.6,"baseSeverity":"MEDIUM","confidentialityImpact":"LOW","integrityImpact":"LOW","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"REQUIRED","vectorString":"CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
2 source assertions{"cweId":"CWE-78","description":"CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/problemTypes/0/descriptions/0
{"cweId":"CWE-20","description":"CWE-20: Improper Input Validation","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/problemTypes/1/descriptions/0
Source references
3 source assertions{"name":"https://github.com/1Panel-dev/MaxKB/commit/50e96002ee5dca34c68d3d9333b64ea358c92304","tags":["x_refsource_MISC"],"url":"https://github.com/1Panel-dev/MaxKB/commit/50e96002ee5dca34c68d3d9333b64ea358c92304"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/references/1
{"name":"https://github.com/1Panel-dev/MaxKB/releases/tag/v2.8.0","tags":["x_refsource_MISC"],"url":"https://github.com/1Panel-dev/MaxKB/releases/tag/v2.8.0"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/references/2
{"name":"https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-pw52-326g-r5xj","tags":["x_refsource_CONFIRM"],"url":"https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-pw52-326g-r5xj"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:31193966fcb768d9b1f7c2ef715dfe75e2316e2c11e52d7837828b8a49e23cf0 · sha256:22b232ffed6f4020… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.