CVE-2025-53927

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use the `shutil.copy2` method in Python to copy the command they want to execute to the executable directory. This bypasses directory restrictions and reverse shell. Version 2.0.0 fixes the issue.
Configurations

No configuration.

History

17 Jul 2025, 14:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-07-17 14:15

Updated : 2025-07-17 21:15


NVD link : CVE-2025-53927

Mitre link : CVE-2025-53927

CVE.ORG link : CVE-2025-53927


JSON object : View

Products Affected

No product.

CWE
CWE-94

Improper Control of Generation of Code ('Code Injection')