PT-2026-32574 · Maxkb · Maxkb

Liqiang-Fit2Cloud

·

Published

2026-04-14

·

Updated

2026-04-14

·

CVE-2026-39420

CVSS v3.1

7.4

High

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:L/I:L/A:L
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.8.0
Description An incomplete sandbox protection mechanism allows an authenticated user with tool execution privileges to escape the LD PRELOAD-based sandbox. The system restricts untrusted Python code execution via the 'Tool Debug API' by injecting sandbox.so through the LD PRELOAD environment variable to intercept sensitive C library functions such as execve, socket, and open. However, because the /usr/bin/env utility can be executed, an attacker can run the env -i python command. The -i flag clears all environment variables, including LD PRELOAD, which removes the sandbox.so hook. This allows the newly spawned Python process to execute natively, resulting in unrestricted Remote Code Execution (RCE) and network access.
Recommendations Update to version 2.8.0.

Fix

Protection Mechanism Failure

OS Command Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39420

Affected Products

Maxkb