← all CVEs

CVE-2026-79918

MaxKB: Sandbox escape via unhooked fexecve

Published 21 Sep 2026Updated 21 Sep 2026

Severity: MEDIUM

6.3

CVSS Base Score

Description

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.

Affected products (1)

  • 1Panel-dev MaxKB

Problem types

  • CWE-693: Protection Mechanism Failure

Get alerted the moment a CVE like this matches your stack.

Create a free account