PT-2026-32574 · Maxkb · Maxkb
Liqiang-Fit2Cloud
·
Published
2026-04-14
·
Updated
2026-04-14
·
CVE-2026-39420
CVSS v3.1
7.4
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
MaxKB versions prior to 2.8.0
Description
An incomplete sandbox protection mechanism allows an authenticated user with tool execution privileges to escape the LD PRELOAD-based sandbox. The system restricts untrusted Python code execution via the 'Tool Debug API' by injecting
sandbox.so through the LD PRELOAD environment variable to intercept sensitive C library functions such as execve, socket, and open. However, because the /usr/bin/env utility can be executed, an attacker can run the env -i python command. The -i flag clears all environment variables, including LD PRELOAD, which removes the sandbox.so hook. This allows the newly spawned Python process to execute natively, resulting in unrestricted Remote Code Execution (RCE) and network access.Recommendations
Update to version 2.8.0.
Fix
Protection Mechanism Failure
OS Command Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Maxkb