Technology · 1Panel-dev
1Panel-dev MaxKB vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 17 vulnerabilities in 1Panel-dev MaxKB: 8 in the last 7 days and 10 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-77525, was published on 21 September 2026.
- Last 7 days
- 8
- Last 90 days
- 10
- Critical, all time
- 1
- Exploited in the wild
- 0
About 1Panel-dev MaxKB
MaxKB is an open-source knowledge base question and answering system based on Large Language Models.
Latest 1Panel-dev MaxKB vulnerabilities
- CVE-2026-77525: MaxKB chat-record routes authorization bypass in management APImediumCVSS 4.2EPSS 0.2%
- CVE-2026-77523: MaxKB cross-workspace model parameter form writehighCVSS 7.4EPSS 0.3%
- CVE-2026-77522: MaxKB knowledge web-document crawler server-side request forgerymediumCVSS 4.3EPSS 0.3%
- CVE-2026-77521: MaxKB command execution in SandboxShellBackendcriticalCVSS 10EPSS 1.1%
- CVE-2026-77520: MaxKB authorization bypass in application discovery and invocationmediumCVSS 5.4EPSS 0.2%
- CVE-2026-77519: MaxKB expired application API keys remain usable on MCP endpointmediumCVSS 5.4EPSS 0.2%
- CVE-2026-77518: MaxKB authorization bypass exposes MCP tool configurationmediumCVSS 5EPSS 0.3%
- CVE-2026-77517: MaxKB authorization bypass in document and paragraph routesmediumCVSS 5.4EPSS 0.2%
- CVE-2026-64870: 1Panel-dev MaxKB SSRF in UpdateStoreToolinfoCVSS 5.3
- CVE-2026-54149: 1Panel-dev MaxKB command injection in MCP tool importhighCVSS 8.8
- CVE-2026-56779: 1Panel-dev MaxKB SSRF in ToolSerializer endpointsmediumCVSS 6.4
- CVE-2026-45413: MaxKB unsalted MD5 password hashinginfoCVSS 6.9
- CVE-2026-45412: 1Panel-dev MaxKB SSRF in workflow template importinfoCVSS 6.3
- CVE-2026-44847: MaxKB authentication bypass in webhook trigger endpointhighCVSS 7.5
- CVE-2026-42337: 1Panel-dev MaxKB broken access control in OSS URL fetch APIinfoCVSS 5.3
- CVE-2026-42336: 1Panel-dev MaxKB SSRF bypass in OSS file serviceinfoCVSS 5.1
- CVE-2026-42335: 1Panel-dev MaxKB SSRF in OSS file service URL fetchinfoCVSS 6.3
Most severe 1Panel-dev MaxKB vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2026-77521: MaxKB command execution in SandboxShellBackendcriticalCVSS 10EPSS 1.1%
- CVE-2026-54149: 1Panel-dev MaxKB command injection in MCP tool importhighCVSS 8.8
- CVE-2026-44847: MaxKB authentication bypass in webhook trigger endpointhighCVSS 7.5
- CVE-2026-77523: MaxKB cross-workspace model parameter form writehighCVSS 7.4EPSS 0.3%
- CVE-2026-56779: 1Panel-dev MaxKB SSRF in ToolSerializer endpointsmediumCVSS 6.4
- CVE-2026-77519: MaxKB expired application API keys remain usable on MCP endpointmediumCVSS 5.4EPSS 0.2%
- CVE-2026-77520: MaxKB authorization bypass in application discovery and invocationmediumCVSS 5.4EPSS 0.2%
- CVE-2026-77517: MaxKB authorization bypass in document and paragraph routesmediumCVSS 5.4EPSS 0.2%
- CVE-2026-77518: MaxKB authorization bypass exposes MCP tool configurationmediumCVSS 5EPSS 0.3%
- CVE-2026-77522: MaxKB knowledge web-document crawler server-side request forgerymediumCVSS 4.3EPSS 0.3%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 29 Jun 2026 | 0 | 0 | |
| 6 Jul 2026 | 1 | 0 | |
| 13 Jul 2026 | 0 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 1 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 8 | 1 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/maxkb.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "1Panel-dev MaxKB vulnerabilities", https://junglewise.ai/threats/technologies/maxkb, 26 September 2026.