CVE-2026-39418General(maxkb / maxkb)

LOWCVSS 7.4 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSG_FASTOPEN flag. This allows authenticated user with tool-editing permissions to reach internal services that are explicitly blocked by the sandbox's banned hosts configuration. MaxKB's sandbox uses LD_PRELOAD to hook the connect() function and block connections to banned IPs, but Linux's sendto() with the MSG_FASTOPEN flag can establish TCP connections directly through the kernel without ever calling connect(), completely bypassing the IP validation. Although sendto is listed in the syscall() wrapper, this is ineffective because glibc invokes the kernel syscall directly rather than routing through the hooked syscall() function. This issue has been fixed in version 2.8.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • maxkb

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
maxkb

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-14: 3Technical Details · 2026-04-14: 204-14
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-39418 📊 Severity: 5.0 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-39418 #CVE-2026-39418 #CVE #Medium #CyberSecurity #InfoSec https://t.co/JWpGlR0tQ2

    Post summary

    The tweet announces CVE-2026-39418 as a medium‑severity vulnerability affecting unspecified products, but provides no technical details, PoC, exploit, or patch information.

    0000027
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39418 Sandbox Network Protection Bypass in MaxKB Versions 2.7.1 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39418

    Post summary

    Announcement of a sandbox protection bypass in MaxKB 2.7.1 and earlier, without PoC, exploit, patch, or exploitation evidence.

    0000063
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39418 MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSG_FAS… https://www.cve.org/CVERecord?id=CVE-2026-39418

    Post summary

    A disclosure of CVE-2026-39418 reporting a sandbox bypass in MaxKB via socket.sendto(); no PoC, exploit, active use, or patch details are mentioned.

    0000083
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmaxkbmaxkb---

Explore more