PT-2026-96257 · Maxkb · Maxkb

CVE-2026-77521

·

Published

2026-09-21

·

Updated

2026-09-26

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.10.5-lts
Description Assistants utilizing a tool, MCP tool, skill, or sub-application use the SandboxShellBackend, which exposes an execute shell tool. Because the execute function is omitted from the interrupt on configuration, commands can be run without requiring human approval. This allows untrusted chat input or ingested content to trigger remote command execution via prompt injection. In source deployments where MAXKB SANDBOX is disabled, commands are executed directly as the application user. Additionally, the official root container employs a string-based gosu wrapper that allows shell metacharacters to execute outside the intended sandbox.
Recommendations Update to version 2.10.5-lts.

Exploit

Fix

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-77521
GHSA-F36J-F34J-H3RX

Affected Products

Maxkb