PT-2026-32583 · Maxkb · Maxkb

Lowliqiang

·

Published

2026-04-14

·

Updated

2026-04-14

·

CVE-2026-39419

CVSS v3.1

3.1

Low

VectorAV:N/AC:H/PR:L/UI:N/S:U/C:N/I:L/A:N
Name of the Vulnerable Software and Affected Versions MaxKB versions prior to 2.8.0
Description An authenticated user can bypass sandbox result validation and spoof tool execution results. This is achieved by exploiting Python frame introspection to read the wrapper's UUID from its bytecode constants and writing a forged result directly to file descriptor 1, which bypasses stdout redirection. By calling the sys.exit(0) function, the attacker terminates the wrapper before the legitimate output is printed, leading the service to trust the spoofed response as the genuine tool result.
Recommendations Update to version 2.8.0.

Fix

Authentication Bypass by Spoofing

Protection Mechanism Failure

Special Elements Injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-39419

Affected Products

Maxkb