CVE-2026-39425Disclosure(maxkb / maxkb)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability that allows authenticated users to inject arbitrary HTML and JavaScript into the Application prologue (Opening Remarks) field by wrapping malicious payloads in <html_rander> tags. The backend fails to sanitize or encode HTML entities in the prologue field when applications are created or updated via the /admin/api/workspace/{workspace_id}/application endpoint, storing the raw payload directly in the database. The frontend then renders this content using an innerHTML-equivalent mechanism, trusting <html_rander>-wrapped content to be safe, which enables persistent DOM-based Stored XSS execution against any visitor who opens the affected chatbot interface. Exploitation can lead to session hijacking, unauthorized actions performed on behalf of victims (such as deleting workspaces or applications), and sensitive data exposure. This issue has been fixed in version 2.8.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-80

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • maxkb

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
maxkb

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-14: 3Technical Details · 2026-04-14: 204-14
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-39425 📊 Severity: 5.1 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-39425 #CVE-2026-39425 #CVE #Medium #CyberSecurity #InfoSec https://t.co/ngTQ2rZIfp

    Post summary

    The tweet announces CVE-2026-39425 and notes a medium severity rating, but offers no detailed technical information, exploits, or mitigation guidance.

    0000030
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39425 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability that allows authenticated user… https://www.cve.org/CVERecord?id=CVE-2026-39425

    Post summary

    The tweet announces CVE‑2026‑39425, a stored XSS flaw in MaxKB versions 2.7.1 and older that can be leveraged by authenticated users. No PoC, exploit code, active exploitation, or patch information is provided.

    0000059
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39425 Stored Cross-Site Scripting in MaxKB Versions 2.7.1 and Below https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39425

    Post summary

    The statement reports a stored XSS vulnerability (CVE-2026‑39425) affecting MaxKB versions 2.7.1 and earlier, with a link to additional details.

    0000015
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmaxkbmaxkb---

Explore more