PT-2026-32578 · Maxkb · Maxkb

·

CVE-2026-39424

·

Published

2026-04-14

·

Updated

2026-04-14

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.8.0
Description The chat export feature fails to properly sanitize strings starting with formula characters when an administrator exports application chat history to an Excel file (.xlsx) via the '/admin/api/workspace/{workspace id}/application/{application id}/chat/export' endpoint. This can lead to Arbitrary Code Execution (RCE) on the administrator workstation through Dynamic Data Exchange (DDE), a protocol that allows applications to share data and execute commands.
Recommendations Update to version 2.8.0.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39424
GHSA-RR4R-7CJ2-29VP

Affected Products

Maxkb