MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting with the AI chat interface to execute arbitrary JavaScript in the browsers of other users, including administrators, resulting in Stored Cross-Site Scripting (XSS). This issue has been fixed in version 2.8.0.
References
Configurations
History
20 Apr 2026, 17:34
| Type | Values Removed | Values Added |
|---|---|---|
| CVSS |
v2 : v3 : |
v2 : unknown
v3 : 5.4 |
| First Time |
Maxkb maxkb
Maxkb |
|
| CPE | cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:* | |
| References | () https://github.com/1Panel-dev/MaxKB/commit/34fb95bde9574c5b3a734ab00c7f29b9e7d32669 - Patch | |
| References | () https://github.com/1Panel-dev/MaxKB/releases/tag/v2.8.0 - Release Notes | |
| References | () https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-462x-99gf-mp79 - Vendor Advisory |
14 Apr 2026, 01:16
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-14 01:16
Updated : 2026-04-20 17:34
NVD link : CVE-2026-39423
Mitre link : CVE-2026-39423
CVE.ORG link : CVE-2026-39423
JSON object : View
Products Affected
maxkb
- maxkb
