Maxkb · Maxkb · CVE-2026-45412
**Name of the Vulnerable Software and Affected Versions**
MaxKB versions prior to 2.9.1
**Description**
Authenticated users can perform Server-Side Request Forgery (SSRF) during the import of a work flow template. The application fetches arbitrary URLs provided in the `downloadUrl` variable of the `work flow template` without performing URL validation or internal IP filtering. SSRF is a flaw that allows an attacker to induce the server-side application to make requests to an unintended location.
**Recommendations**
Update to version 2.9.1.