
CVE-2026-39422 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability through the application name o… https://www.cve.org/CVERecord?id=CVE-2026-39422
Post summary
This brief note announces that MaxKB versions 2.7.1 and earlier are vulnerable to a stored XSS flaw via the application name field.


