MEDIUM 6.3 NVD
CVE-2026-79918
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to pre
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.
References
- https://github.com/1Panel-dev/MaxKB/commit/6fa7947a85030b87977c4026f33af11ca10dd1e6
- https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.6-lts
- https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-9mh9-v949-fwqh
This medium severity vulnerability with a CVSS score of 6.3 was published on 2026-09-21 via NVD.
vulnfeed aggregates 14328 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.