MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0.
Metrics
Affected Vendors & Products
References
History
Mon, 15 Dec 2025 18:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maxkb
Maxkb maxkb |
|
| CPEs | cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Maxkb
Maxkb maxkb |
Fri, 12 Dec 2025 09:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel maxkb |
|
| Vendors & Products |
1panel
1panel maxkb |
Thu, 11 Dec 2025 22:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0. | |
| Title | MaxKB has a Python sandbox LD_PRELOAD bypass | |
| Weaknesses | CWE-362 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published: 2025-12-11T21:47:22.479Z
Updated: 2025-12-11T21:47:22.479Z
Reserved: 2025-12-01T18:22:06.864Z
Link: CVE-2025-66446
No data.
Status : Analyzed
Published: 2025-12-11T22:15:55.987
Modified: 2025-12-15T17:58:54.180
Link: CVE-2025-66446
No data.