MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.
Metrics
Affected Vendors & Products
References
History
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel maxkb |
|
| Vendors & Products |
1panel
1panel maxkb |
Thu, 11 Dec 2025 21:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0. | |
| Title | MaxKB vulnerable to privilege escalation through sandbox bypass | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-11T21:39:15.361Z
Updated: 2025-12-11T21:39:15.361Z
Reserved: 2025-11-28T23:33:56.367Z
Link: CVE-2025-66419
No data.
Status : Undergoing Analysis
Published: 2025-12-11T22:15:55.817
Modified: 2025-12-12T15:17:31.973
Link: CVE-2025-66419
No data.
ReportizFlow