PT-2026-32129 · Unknown · 1Panel-Dev Maxkb
Ana10Gy
·
Published
2026-04-12
·
Updated
2026-04-12
·
CVE-2026-6108
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
1Panel-dev MaxKB versions up to 2.6.1
Description
A vulnerability exists in the
execute function within the file apps/application/flow/step node/mcp node/impl/base mcp node.py of the Model Context Protocol Node component. Manipulation of this function can lead to operating system command injection, potentially allowing remote attackers to execute arbitrary commands. The exploit has been publicly disclosed.Recommendations
Upgrade the affected component to a fixed version.
Exploit
Fix
OS Command Injection
Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
1Panel-Dev Maxkb