CVE-2026-39426Disclosure(maxkb / maxkb)

LOWCVSS 5.4 · MEDIUM

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom <iframe_render> tags from LLM responses or Application Prologue configurations, bypassing standard Markdown sanitization and XSS filtering. The unsanitized HTML content is passed to the IframeRender.vue component, which renders it directly into an <iframe> via the srcdoc attribute configured with sandbox="allow-scripts allow-same-origin". This can be a dangerous combination, allowing injected scripts to escape the iframe and execute JavaScript in the parent window using window.parent. Since the Prologue is rendered for any user visiting an application's chat interface, this results in a high-impact Stored XSS that can lead to session hijacking, unauthorized actions, and sensitive data exposure. This issue has been fixed in version 2.8.0.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-79

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • maxkb

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • General: 1 classified signal
  • 3 total mentions across 1 day

Affected systems

Vendors
Products
maxkb

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-04-14: 3Technical Details · 2026-04-14: 204-14
Signal classification2 categories
Disclosure
266.7%
General
133.3%
Referenced assets3 URLs
Full discourse3 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-39426 📊 Severity: 5.1 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-39426 #CVE-2026-39426 #CVE #Medium #CyberSecurity #InfoSec https://t.co/57QkZWh7Xm

    Post summary

    A brief CVE alert stating severity and general product impact, with no additional technical details, PoC, exploit, or patch information.

    0000028
    137 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39426 MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRendere… https://www.cve.org/CVERecord?id=CVE-2026-39426

    Post summary

    The post announces CVE‑2026‑39426, noting a stored XSS flaw in MaxKB’s MdRendere component affecting versions 2.7.1 and earlier.

    0000051
    57.2K followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39426 Stored Cross-Site Scripting in MaxKB Versions 2.7.1 and Below via IframeRender https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39426

    Post summary

    The content reports a new stored XSS vulnerability (CVE‑2026‑39426) affecting MaxKB 2.7.1 and earlier, via IframeRender, but does not mention a PoC, exploit, patch, or active exploitation.

    0000024
    4.0K followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmaxkbmaxkb---

Explore more