CVE-2026-39417

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execution vulnerability still exists in the MCP node of the workflow engine. MaxKB only restricts the referencing code path (loading MCP config from the database). The else branch, responsible for loading mcp_servers directly from user-supplied JSON remains completely unpatched. Since mcp_source is an optional field (required=False), an attacker can simply omit it or set it to any non-referencing value to bypass the fix. By calling the workflow creation API directly with a crafted JSON payload, an attacker can inject a complete MCP node configuration with stdio transport, arbitrary command, and args — achieving RCE when the workflow is triggered via chat. This issue has been fixed in version 2.8.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:*

History

20 Apr 2026, 17:36

Type Values Removed Values Added
CPE cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:*
References () https://github.com/1Panel-dev/MaxKB/commit/50e96002ee5dca34c68d3d9333b64ea358c92304 - () https://github.com/1Panel-dev/MaxKB/commit/50e96002ee5dca34c68d3d9333b64ea358c92304 - Patch
References () https://github.com/1Panel-dev/MaxKB/releases/tag/v2.8.0 - () https://github.com/1Panel-dev/MaxKB/releases/tag/v2.8.0 - Release Notes
References () https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-pw52-326g-r5xj - () https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-pw52-326g-r5xj - Vendor Advisory
First Time Maxkb maxkb
Maxkb

14 Apr 2026, 00:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 00:16

Updated : 2026-04-20 17:36


NVD link : CVE-2026-39417

Mitre link : CVE-2026-39417

CVE.ORG link : CVE-2026-39417


JSON object : View

Products Affected

maxkb

  • maxkb
CWE
CWE-20

Improper Input Validation

CWE-78

Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection')