
One AI assistant, two separate paths to root (CVSS 10.0 and 9.1). CVE-2026-77521: MaxKB's tool and MCP agents expose a shell-execute function without human approval, so untrusted chat content alone can trigger command execution. CVE-2026-79916: A workspace member can inject control characters into AWS Bedrock credential fields, planting a malicious profile that runs an attacker's command as root. Both fixed in MaxKB 2.10.5-lts. Update now. Details: http://vulntracker.io/cves/CVE-2026-77521 #MaxKB #CVE #AI #PromptInjection #InfoSec #CyberSecurity
