Executive brief
MaxKB is an open-source AI assistant used by enterprises to build knowledge bases and chat interfaces. A security flaw allows logged-in users to trick the system into making unauthorized network requests to internal servers that should be private. This could allow an attacker to probe internal infrastructure or access sensitive internal services that are not exposed to the internet.
Technical details
A Server-Side Request Forgery (SSRF) vulnerability exists in the /chat/api/oss/get_url endpoint due to a URL parsing discrepancy. The application uses Python's 'urlparse' for validation but the 'requests' library for the actual HTTP call. An attacker can provide a malformed URL (e.g., using backslashes and @ symbols) that 'urlparse' interprets as a safe external host while 'requests' interprets as an internal IP address. This allows authenticated attackers to bypass security filters and reach internal network services. The issue is resolved in version 2.8.1 by unifying the parsing logic.
Affected products
- 1Panel-dev MaxKB <= 2.8.0
Timeline
- 2026-05-06: advisory: GitHub Security Advisory published
- 2026-05-26: disclosed: CVE published to NVD