PT-2026-32129 · Unknown · 1Panel-Dev Maxkb

Ana10Gy

·

Published

2026-04-12

·

Updated

2026-04-12

·

CVE-2026-6108

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions 1Panel-dev MaxKB versions up to 2.6.1
Description A vulnerability exists in the execute function within the file apps/application/flow/step node/mcp node/impl/base mcp node.py of the Model Context Protocol Node component. Manipulation of this function can lead to operating system command injection, potentially allowing remote attackers to execute arbitrary commands. The exploit has been publicly disclosed.
Recommendations Upgrade the affected component to a fixed version.

Exploit

Fix

OS Command Injection

Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6108

Affected Products

1Panel-Dev Maxkb