CRITICAL 10.0 CVE-2026-77521 Published 21 Sept 2026

MaxKB AI Assistant Command Execution Vulnerability

Worried this affects your website?

MaxKB, an open-source AI assistant for enterprise, is affected by a command execution vulnerability fixed in version 2.10.5-lts.

Before that release, assistants using a tool, MCP tool, skill, or sub-application rely on SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore trigger command execution.

  • Source deployments with MAXKB_SANDBOX disabled run commands directly as the application user.
  • The official root container's string-based gosu wrapper allowed shell metacharacters to execute outside the intended sandbox.

The issue is fixed in version 2.10.5-lts.

Reference: CVE-2026-77521 on NVD

← Back to Security News