
🚨High - MaxKB Command Injection via Malicious MCP stdio Tool Import (CVE-2026-54149) MaxKB's tool-import serializer and MCP referencing mode don't consistently validate the MCP transport type. An authenticated user can import a .tool file specifying stdio transport with malicious commands, then trigger it through an AI Chat node - causing MultiServerMCPClient to execute arbitrary system commands on the server. Since MCP stdio transport launches local processes, an unvalidated stdio tool definition is effectively arbitrary command execution. Only a low-privileged authenticated account is required (CVSS 8.8). 👉Upgrade MaxKB to 2.10.0-lts.
Post summary
CVE‑2026‑54149 exposes command injection via Malicious MCP stdio tool import in MaxKB, allowing authenticated low‑privileged users to execute arbitrary system commands; upgrading to MaxKB 2.10.0‑lts resolves the flaw.

