MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability allow privileged users to create a reverse shell. This vulnerability is fixed in v1.10.4-lts.
References
Configurations
History
01 Aug 2025, 21:10
Type | Values Removed | Values Added |
---|---|---|
First Time |
Maxkb maxkb
Maxkb |
|
CPE | cpe:2.3:a:maxkb:maxkb:*:*:*:*:lts:*:*:* | |
References | () https://github.com/1Panel-dev/MaxKB/commit/4ae02c8d3eb65542c88ef58c0abd94c52c949d8f - Patch | |
References | () https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-fjf6-6cvf-xr72 - Vendor Advisory |
11 Apr 2025, 15:39
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
10 Apr 2025, 14:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-10 14:15
Updated : 2025-08-01 21:10
NVD link : CVE-2025-32383
Mitre link : CVE-2025-32383
CVE.ORG link : CVE-2025-32383
JSON object : View
Products Affected
maxkb
- maxkb
CWE
CWE-94
Improper Control of Generation of Code ('Code Injection')