PT-2025-50768 · Maxkb · Maxkb

Published

2025-12-11

·

Updated

2025-12-12

·

CVE-2025-66419

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.4.0
Description MaxKB, an open-source AI assistant for enterprise, contains a flaw in the tool module that allows an attacker to escape the sandbox environment and gain elevated privileges. This occurs under specific concurrent conditions.
Recommendations Update to version 2.4.0 or later.

Exploit

Fix

LPE

Race Condition

Weakness Enumeration

Related Identifiers

CVE-2025-66419
GHSA-F9QM-2PXQ-FX6C

Affected Products

Maxkb