PT-2026-32578 · Maxkb · Maxkb

Shaohuzhang1

·

Published

2026-04-14

·

Updated

2026-04-14

·

CVE-2026-39424

CVSS v4.0

5.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.8.0
Description The chat export feature fails to properly sanitize strings starting with formula characters when an administrator exports application chat history to an Excel file (.xlsx) via the '/admin/api/workspace/{workspace id}/application/{application id}/chat/export' endpoint. This can lead to Arbitrary Code Execution (RCE) on the administrator workstation through Dynamic Data Exchange (DDE), a protocol that allows applications to share data and execute commands.
Recommendations Update to version 2.8.0.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-39424

Affected Products

Maxkb