Executive brief
MaxKB is an open-source AI assistant that helps enterprises manage knowledge documents. An authenticated user can trick the document import crawler into fetching URLs on internal networks or cloud metadata services, allowing them to read sensitive data like cloud credentials or internal API responses. This could lead to full compromise of cloud accounts or exposure of confidential internal systems.
Technical details
The vulnerability is a non-blind server-side request forgery (SSRF) in the Fork crawler used for web-document import and synchronization. The crawler accepts user-supplied URLs and calls requests.get with verify=False, no URL scheme validation, and no blocklist for loopback, link-local, or private IP ranges; the fetched response body is returned to the authenticated user. An attacker with any authenticated workspace user role can target internal services (127.0.0.1, 169.254.169.254) or private networks to exfiltrate cloud metadata, credentials, or internal API responses.
Affected products
- 1Panel-dev MaxKB 2.10.3-lts and earlier
Timeline
- 2026-09-21: disclosed
- other: No fixed version available as of advisory review