{"schema_version":1,"title":"1Panel-dev MaxKB vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 17 vulnerabilities in 1Panel-dev MaxKB: 8 in the last 7 days and 10 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2026-77525, was published on 21 September 2026.","url":"https://junglewise.ai/threats/technologies/maxkb","json_url":"https://junglewise.ai/threats/technologies/maxkb.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/maxkb","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":3,"all_time":17,"critical":1,"exploited":0,"last_7_days":8,"last_30_days":8,"last_90_days":10,"last_365_days":17},"latest":[{"cve":"CVE-2026-77525","cvss":4.2,"epss":0.002,"slug":"cve-2026-77525-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts","title":"MaxKB chat-record routes authorization bypass in management API","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:11.463+00:00","url":"https://junglewise.ai/threats/cve-2026-77525-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts"},{"cve":"CVE-2026-77523","cvss":7.4,"epss":0.0026,"slug":"cve-2026-77523-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2","title":"MaxKB cross-workspace model parameter form write","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:11.28+00:00","url":"https://junglewise.ai/threats/cve-2026-77523-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2"},{"cve":"CVE-2026-77522","cvss":4.3,"epss":0.003,"slug":"cve-2026-77522-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2","title":"MaxKB knowledge web-document crawler server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:11.12+00:00","url":"https://junglewise.ai/threats/cve-2026-77522-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2"},{"cve":"CVE-2026-77521","cvss":10,"epss":0.0105,"slug":"cve-2026-77521-maxkb-is-an-open-source-ai-assistant-for-enterprise-prior-to","title":"MaxKB command execution in SandboxShellBackend","severity":"critical","exploited":false,"published_at":"2026-09-21T21:17:10.943+00:00","url":"https://junglewise.ai/threats/cve-2026-77521-maxkb-is-an-open-source-ai-assistant-for-enterprise-prior-to"},{"cve":"CVE-2026-77520","cvss":5.4,"epss":0.0023,"slug":"cve-2026-77520-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts","title":"MaxKB authorization bypass in application discovery and invocation","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.787+00:00","url":"https://junglewise.ai/threats/cve-2026-77520-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts"},{"cve":"CVE-2026-77519","cvss":5.4,"epss":0.0024,"slug":"cve-2026-77519-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts","title":"MaxKB expired application API keys remain usable on MCP endpoint","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.633+00:00","url":"https://junglewise.ai/threats/cve-2026-77519-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts"},{"cve":"CVE-2026-77518","cvss":5,"epss":0.0027,"slug":"cve-2026-77518-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts","title":"MaxKB authorization bypass exposes MCP tool configuration","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.477+00:00","url":"https://junglewise.ai/threats/cve-2026-77518-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts"},{"cve":"CVE-2026-77517","cvss":5.4,"epss":0.0023,"slug":"cve-2026-77517-maxkb-is-an-open-source-ai-assistant-for-enterprise-from-version","title":"MaxKB authorization bypass in document and paragraph routes","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.317+00:00","url":"https://junglewise.ai/threats/cve-2026-77517-maxkb-is-an-open-source-ai-assistant-for-enterprise-from-version"},{"cve":"CVE-2026-64870","cvss":5.3,"slug":"cve-2026-64870-1panel-dev-maxkb-ssrf-in-updatestoretool","title":"1Panel-dev MaxKB SSRF in UpdateStoreTool","severity":"info","exploited":false,"published_at":"2026-07-30T19:18:35.397+00:00","url":"https://junglewise.ai/threats/cve-2026-64870-1panel-dev-maxkb-ssrf-in-updatestoretool"},{"cve":"CVE-2026-54149","cvss":8.8,"slug":"cve-2026-54149-1panel-dev-maxkb-command-injection-in-mcp-tool-import","title":"1Panel-dev MaxKB command injection in MCP tool import","severity":"high","exploited":false,"published_at":"2026-07-10T16:16:32.587+00:00","url":"https://junglewise.ai/threats/cve-2026-54149-1panel-dev-maxkb-command-injection-in-mcp-tool-import"},{"cve":"CVE-2026-56779","cvss":6.4,"slug":"cve-2026-56779-1panel-dev-maxkb-ssrf-in-toolserializer-endpoints","title":"1Panel-dev MaxKB SSRF in ToolSerializer endpoints","severity":"medium","exploited":false,"published_at":"2026-06-25T19:16:44.833+00:00","url":"https://junglewise.ai/threats/cve-2026-56779-1panel-dev-maxkb-ssrf-in-toolserializer-endpoints"},{"cve":"CVE-2026-45413","cvss":6.9,"slug":"cve-2026-45413-maxkb-unsalted-md5-password-hashing","title":"MaxKB unsalted MD5 password hashing","severity":"info","exploited":false,"published_at":"2026-05-26T21:16:40.233+00:00","url":"https://junglewise.ai/threats/cve-2026-45413-maxkb-unsalted-md5-password-hashing"},{"cve":"CVE-2026-45412","cvss":6.3,"slug":"cve-2026-45412-1panel-dev-maxkb-ssrf-in-workflow-template-import","title":"1Panel-dev MaxKB SSRF in workflow template import","severity":"info","exploited":false,"published_at":"2026-05-26T21:16:40.097+00:00","url":"https://junglewise.ai/threats/cve-2026-45412-1panel-dev-maxkb-ssrf-in-workflow-template-import"},{"cve":"CVE-2026-44847","cvss":7.5,"slug":"cve-2026-44847-maxkb-authentication-bypass-in-webhook-trigger-endpoint","title":"MaxKB authentication bypass in webhook trigger endpoint","severity":"high","exploited":false,"published_at":"2026-05-26T21:16:39.313+00:00","url":"https://junglewise.ai/threats/cve-2026-44847-maxkb-authentication-bypass-in-webhook-trigger-endpoint"},{"cve":"CVE-2026-42337","cvss":5.3,"slug":"cve-2026-42337-1panel-dev-maxkb-broken-access-control-in-oss-url-fetch-api","title":"1Panel-dev MaxKB broken access control in OSS URL fetch API","severity":"info","exploited":false,"published_at":"2026-05-26T21:16:37.317+00:00","url":"https://junglewise.ai/threats/cve-2026-42337-1panel-dev-maxkb-broken-access-control-in-oss-url-fetch-api"},{"cve":"CVE-2026-42336","cvss":5.1,"slug":"cve-2026-42336-1panel-dev-maxkb-ssrf-bypass-in-oss-file-service","title":"1Panel-dev MaxKB SSRF bypass in OSS file service","severity":"info","exploited":false,"published_at":"2026-05-26T21:16:37.17+00:00","url":"https://junglewise.ai/threats/cve-2026-42336-1panel-dev-maxkb-ssrf-bypass-in-oss-file-service"},{"cve":"CVE-2026-42335","cvss":6.3,"slug":"cve-2026-42335-1panel-dev-maxkb-ssrf-in-oss-file-service-url-fetch","title":"1Panel-dev MaxKB SSRF in OSS file service URL fetch","severity":"info","exploited":false,"published_at":"2026-05-26T21:16:37.017+00:00","url":"https://junglewise.ai/threats/cve-2026-42335-1panel-dev-maxkb-ssrf-in-oss-file-service-url-fetch"}],"weekly":[{"week":"2026-06-29","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":1,"exploited":0,"vulnerabilities":8}],"related":[{"name":"1Panel-dev 1Panel","slug":"1panel","vulnerabilities":7,"url":"https://junglewise.ai/threats/technologies/1panel"},{"name":"1Panel-dev CordysCRM","slug":"cordyscrm","vulnerabilities":4,"url":"https://junglewise.ai/threats/technologies/cordyscrm"}],"technology":{"hub":true,"name":"1Panel-dev MaxKB","slug":"maxkb","vendor":{"name":"1Panel-dev","slug":"1panel-dev","url":"https://junglewise.ai/threats/vendors/1panel-dev"},"aliases":[],"category":"web-application","homepage":"https://maxkb.cn/","repo_url":"https://github.com/1Panel-dev/MaxKB","description":"MaxKB is an open-source knowledge base question and answering system based on Large Language Models.","url":"https://junglewise.ai/threats/technologies/maxkb"},"most_severe":[{"cve":"CVE-2026-77521","cvss":10,"epss":0.0105,"slug":"cve-2026-77521-maxkb-is-an-open-source-ai-assistant-for-enterprise-prior-to","title":"MaxKB command execution in SandboxShellBackend","severity":"critical","exploited":false,"published_at":"2026-09-21T21:17:10.943+00:00","url":"https://junglewise.ai/threats/cve-2026-77521-maxkb-is-an-open-source-ai-assistant-for-enterprise-prior-to"},{"cve":"CVE-2026-54149","cvss":8.8,"slug":"cve-2026-54149-1panel-dev-maxkb-command-injection-in-mcp-tool-import","title":"1Panel-dev MaxKB command injection in MCP tool import","severity":"high","exploited":false,"published_at":"2026-07-10T16:16:32.587+00:00","url":"https://junglewise.ai/threats/cve-2026-54149-1panel-dev-maxkb-command-injection-in-mcp-tool-import"},{"cve":"CVE-2026-44847","cvss":7.5,"slug":"cve-2026-44847-maxkb-authentication-bypass-in-webhook-trigger-endpoint","title":"MaxKB authentication bypass in webhook trigger endpoint","severity":"high","exploited":false,"published_at":"2026-05-26T21:16:39.313+00:00","url":"https://junglewise.ai/threats/cve-2026-44847-maxkb-authentication-bypass-in-webhook-trigger-endpoint"},{"cve":"CVE-2026-77523","cvss":7.4,"epss":0.0026,"slug":"cve-2026-77523-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2","title":"MaxKB cross-workspace model parameter form write","severity":"high","exploited":false,"published_at":"2026-09-21T21:17:11.28+00:00","url":"https://junglewise.ai/threats/cve-2026-77523-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2"},{"cve":"CVE-2026-56779","cvss":6.4,"slug":"cve-2026-56779-1panel-dev-maxkb-ssrf-in-toolserializer-endpoints","title":"1Panel-dev MaxKB SSRF in ToolSerializer endpoints","severity":"medium","exploited":false,"published_at":"2026-06-25T19:16:44.833+00:00","url":"https://junglewise.ai/threats/cve-2026-56779-1panel-dev-maxkb-ssrf-in-toolserializer-endpoints"},{"cve":"CVE-2026-77519","cvss":5.4,"epss":0.0024,"slug":"cve-2026-77519-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts","title":"MaxKB expired application API keys remain usable on MCP endpoint","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.633+00:00","url":"https://junglewise.ai/threats/cve-2026-77519-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts"},{"cve":"CVE-2026-77520","cvss":5.4,"epss":0.0023,"slug":"cve-2026-77520-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts","title":"MaxKB authorization bypass in application discovery and invocation","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.787+00:00","url":"https://junglewise.ai/threats/cve-2026-77520-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts"},{"cve":"CVE-2026-77517","cvss":5.4,"epss":0.0023,"slug":"cve-2026-77517-maxkb-is-an-open-source-ai-assistant-for-enterprise-from-version","title":"MaxKB authorization bypass in document and paragraph routes","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.317+00:00","url":"https://junglewise.ai/threats/cve-2026-77517-maxkb-is-an-open-source-ai-assistant-for-enterprise-from-version"},{"cve":"CVE-2026-77518","cvss":5,"epss":0.0027,"slug":"cve-2026-77518-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts","title":"MaxKB authorization bypass exposes MCP tool configuration","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:10.477+00:00","url":"https://junglewise.ai/threats/cve-2026-77518-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-2-10-2-lts"},{"cve":"CVE-2026-77522","cvss":4.3,"epss":0.003,"slug":"cve-2026-77522-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2","title":"MaxKB knowledge web-document crawler server-side request forgery","severity":"medium","exploited":false,"published_at":"2026-09-21T21:17:11.12+00:00","url":"https://junglewise.ai/threats/cve-2026-77522-maxkb-is-an-open-source-ai-assistant-for-enterprise-in-version-2"}],"generated_at":"2026-09-26T12:07:00.15149+00:00"}