CVE-2026-39417Disclosure(maxkb / maxkb)

LOWCVSS 5.5 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Patch maxkb maxkb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execution vulnerability still exists in the MCP node of the workflow engine. MaxKB only restricts the referencing code path (loading MCP config from the database). The else branch, responsible for loading mcp_servers directly from user-supplied JSON remains completely unpatched. Since mcp_source is an optional field (required=False), an attacker can simply omit it or set it to any non-referencing value to bypass the fix. By calling the workflow creation API directly with a crafted JSON payload, an attacker can inject a complete MCP node configuration with stdio transport, arbitrary command, and args — achieving RCE when the workflow is triggered via chat. This issue has been fixed in version 2.8.0.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-20CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • maxkb

Threat summary

  • Patch or workaround signal is available
  • 3 mentions across 1 observed day

What's happening

  • Patch or workaround mentioned in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
maxkb

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-14: 3Patch / Workaround · 2026-04-14: 1Technical Details · 2026-04-14: 304-14
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-39417 📊 Severity: 4.6 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-39417 #CVE-2026-39417 #CVE #Medium #CyberSecurity #InfoSec https://t.co/D88NDb8eu8

    Post summary

    The tweet announces the newly listed CVE‑2026‑39417 with a CVSS severity of 4.6, but it provides only basic disclosure information without any exploitation, patch, or PoC details.

    0000034
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39417 Remote Code Execution in MaxKB Versions 2.7.1 and Below via MCP Node Configuration https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39417

    Post summary

    The text discloses a CVE-2026-39417 Remote Code Execution vulnerability affecting MaxKB 2.7.1 and earlier, triggered by MCP Node Configuration, with no PoC, exploitation evidence, or patch details present.

    0000042
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39417 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an incomplete fix for CVE-2025-53928, where a Remote Code Execution vulnerabilit… https://www.cve.org/CVERecord?id=CVE-2026-39417

    Post summary

    CVE‑2026‑39417 impacts MaxKB versions 2.7.1 and below, exposing a Remote Code Execution vulnerability; an incomplete patch for a prior CVE is noted, but no PoC or active exploitation is reported.

    00000105
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmaxkbmaxkb---

Explore more