CVE-2026-39423

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting with the AI chat interface to execute arbitrary JavaScript in the browsers of other users, including administrators, resulting in Stored Cross-Site Scripting (XSS). This issue has been fixed in version 2.8.0.
Configurations

Configuration 1 (hide)

cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:*

History

20 Apr 2026, 17:34

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 5.4
First Time Maxkb maxkb
Maxkb
CPE cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:*
References () https://github.com/1Panel-dev/MaxKB/commit/34fb95bde9574c5b3a734ab00c7f29b9e7d32669 - () https://github.com/1Panel-dev/MaxKB/commit/34fb95bde9574c5b3a734ab00c7f29b9e7d32669 - Patch
References () https://github.com/1Panel-dev/MaxKB/releases/tag/v2.8.0 - () https://github.com/1Panel-dev/MaxKB/releases/tag/v2.8.0 - Release Notes
References () https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-462x-99gf-mp79 - () https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-462x-99gf-mp79 - Vendor Advisory

14 Apr 2026, 01:16

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-14 01:16

Updated : 2026-04-20 17:34


NVD link : CVE-2026-39423

Mitre link : CVE-2026-39423

CVE.ORG link : CVE-2026-39423


JSON object : View

Products Affected

maxkb

  • maxkb
CWE
CWE-79

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')

CWE-95

Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection')