CVE-2026-79916

LOWCVSS 9.1 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

MaxKB is an open-source AI assistant for enterprise. Prior to 2.10.5-lts, authenticated workspace members can inject control characters into AWS Bedrock access_key_id and secret_access_key fields that _update_aws_credentials writes to /root/.aws/credentials without safe parsing. An attacker can append a new AWS profile containing credential_process, then select that profile during a later model-validation request so botocore executes an attacker-controlled command as root. This vulnerability is fixed in 2.10.5-lts.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-78

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 1 mentions across 1 observed day

What's happening

  • 1 total mentions across 1 day

Deep dive

Activity timeline1 mentions / 1d
00111Mentions · 2026-09-22: 109-22
Referenced assets1 URL
By indicator
Full discourse1 post
  • VulnTracker@vuln_tracker

    One AI assistant, two separate paths to root (CVSS 10.0 and 9.1). CVE-2026-77521: MaxKB's tool and MCP agents expose a shell-execute function without human approval, so untrusted chat content alone can trigger command execution. CVE-2026-79916: A workspace member can inject control characters into AWS Bedrock credential fields, planting a malicious profile that runs an attacker's command as root. Both fixed in MaxKB 2.10.5-lts. Update now. Details: http://vulntracker.io/cves/CVE-2026-77521 #MaxKB #CVE #AI #PromptInjection #InfoSec #CyberSecurity

    1000030
    759 followersView on X

Explore more