PT-2025-29911 · Maxkb · Maxkb

Happyhacking-K

+1

·

Published

2025-07-17

·

Updated

2025-08-02

·

CVE-2025-53927

CVSS v3.1

6.3

Medium

VectorAV:L/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.0.0
Description MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because the software only restricts the execution permissions of files in a specific directory. An attacker can use the shutil.copy2 method in Python to copy a command to the executable directory, bypassing directory restrictions and enabling reverse shell access.
Recommendations Update to version 2.0.0 or later.

Exploit

Fix

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2025-53927
GHSA-5XHM-4J3V-87M4

Affected Products

Maxkb