Junglewise Threat Intelligence

CVE-2026-42336: 1Panel-dev MaxKB SSRF bypass in OSS file service

CVE-2026-42336 · Severity: info · CVSS 5.1 · Published 2026-05-26

Technologies: 1Panel-dev MaxKB. Vendors: 1Panel-dev.

Executive brief

MaxKB is an open-source AI assistant used by enterprises to build knowledge bases and chat interfaces. A security flaw in how the system fetches files from external links allows an attacker to bypass security filters and reach internal network services that are not supposed to be accessible from the internet. This could lead to the exposure of sensitive internal data or unauthorized access to other systems within the company's private network.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in the /chat/api/oss/get_url endpoint of MaxKB due to a Time-of-Check Time-of-Use (TOCTOU) flaw in DNS resolution. The application performs an initial DNS lookup to validate that a target host is not a private IP address, but then performs a second, independent DNS resolution when executing the actual HTTP request via the 'requests' library. This inconsistency allows for a DNS rebinding attack where an attacker can provide a domain that resolves to a public IP during validation but a private IP during execution. An authenticated attacker can exploit this to bypass internal network restrictions. The vulnerability is fixed in version 2.8.1 by resolving and locking the IP address before the request and validating the connected peer IP.

Affected products

  • 1Panel-dev MaxKB <= 2.8.0

Timeline

  • 2026-05-07: advisory: GitHub Security Advisory published
  • 2026-05-26: disclosed: CVE published to NVD
  • 2026-05-26: patched: Fix confirmed available in version 2.8.1

References

Related threats