PT-2025-50769 · Maxkb · Maxkb

CVE-2025-66446

·

Published

2025-12-11

·

Updated

2025-12-12

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions MaxKB versions 2.3.1 and below
Description MaxKB, an open-source AI assistant for enterprise, is affected by improper file permissions. This allows attackers to overwrite critical files, including the built-in dynamic linker, potentially leading to privilege escalation.
Recommendations Update to version 2.4.0 or later.

Exploit

Fix

LPE

Race Condition

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2025-66446
GHSA-5XX2-3Q9W-JPGF

Affected Products

Maxkb