Aller au contenu

Fiche vulnérabilité

CVE-2025-66419 : faille critique maxkb maxkb (CVSS 10.0)

Description

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.

En bref

Sévérité
Critique (CVSS 10.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Exploitation active
Non signalée par la CISA
Publication
11 déc. 2025
Dernière mise à jour
17 juin 2026

Produits concernés

  • maxkb maxkb

Références

Rechercher une autre vulnérabilité dans la base CVE