PT-2026-32578 · Maxkb · Maxkb
Shaohuzhang1
·
Published
2026-04-14
·
Updated
2026-04-14
·
CVE-2026-39424
CVSS v4.0
5.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
MaxKB versions prior to 2.8.0
Description
The chat export feature fails to properly sanitize strings starting with formula characters when an administrator exports application chat history to an Excel file (.xlsx) via the '/admin/api/workspace/{workspace id}/application/{application id}/chat/export' endpoint. This can lead to Arbitrary Code Execution (RCE) on the administrator workstation through Dynamic Data Exchange (DDE), a protocol that allows applications to share data and execute commands.
Recommendations
Update to version 2.8.0.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Maxkb