CVE-2026-39419Disclosure(maxkb / maxkb)

LOWCVSS 3.1 · LOW

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandbox result validation and spoof tool execution results by exploiting Python frame introspection to read the wrapper's UUID from its bytecode constants, then writing a forged result directly to file descriptor 1 (bypassing stdout redirection). By calling sys.exit(0), the attacker terminates the wrapper before it prints the legitimate output, causing the MaxKB service to parse and trust the spoofed response as the genuine tool result. This issue has been fixed in version 2.8.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-290CWE-693

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • maxkb

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
maxkb

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-14: 3Technical Details · 2026-04-14: 204-14
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-39419 📊 Severity: 3.1 🚨 Risk Level: Low 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-39419 #CVE-2026-39419 #CVE #Low #CyberSecurity #InfoSec https://t.co/3fKXXWtcVB

    Post summary

    A low‑severity CVE (CVE‑2026‑39419) has been announced, with no further technical or exploit details provided.

    0000037
    137 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    General

    CVE-2026-39419 Authenticated Tool Result Spoofing in MaxKB Enterprise AI Assistant 2.7.1 https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39419

    Post summary

    A brief reference to CVE‑2026‑39419 describing authenticated tool result spoofing in MaxKB Enterprise AI Assistant, but lacking details on exploits, patches, or active use.

    0000049
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39419 MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, an authenticated user can bypass sandbox result validation and spoof tool execution … https://www.cve.org/CVERecord?id=CVE-2026-39419

    Post summary

    The text discloses that MaxKB versions 2.7.1 and earlier allow authenticated users to bypass sandbox validation and spoof tool execution, with no PoC, patch, or active exploitation details provided.

    0000063
    57.2K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmaxkbmaxkb---

Explore more