CVE-2026-79918
6.3
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Summary
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| 1Panel-dev | MaxKB | < 2.10.6-lts | affected |
Weaknesses
- CWE-693: CWE-693: Protection Mechanism Failure
References
- https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-9mh9-v949-fwqh
- https://github.com/1Panel-dev/MaxKB/commit/6fa7947a85030b87977c4026f33af11ca10dd1e6
- https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.6-lts
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.