PT-2026-96257 · Maxkb · Maxkb
CVE-2026-77521
·
Published
2026-09-21
·
Updated
2026-09-26
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
MaxKB versions prior to 2.10.5-lts
Description
Assistants utilizing a tool, MCP tool, skill, or sub-application use the
SandboxShellBackend, which exposes an execute shell tool. Because the execute function is omitted from the interrupt on configuration, commands can be run without requiring human approval. This allows untrusted chat input or ingested content to trigger remote command execution via prompt injection. In source deployments where MAXKB SANDBOX is disabled, commands are executed directly as the application user. Additionally, the official root container employs a string-based gosu wrapper that allows shell metacharacters to execute outside the intended sandbox.Recommendations
Update to version 2.10.5-lts.
Exploit
Fix
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Maxkb