MaxKB Remote Command Execution Vulnerability in Function Library Module

Vulnerability

A remote command execution vulnerability has been identified in MaxKB, an open-source knowledge base question-answering system that utilizes a large language model and retrieval-augmented generation. This vulnerability, present in versions prior to 1.9.0, allows privileged users to execute operating system commands within custom scripts. The issue has been addressed in version 1.9.0.

Impact

Exploitation of this vulnerability allows privileged users to execute arbitrary operating system commands on the server where MaxKB is running, potentially leading to unauthorized access or modification of system files and processes.

Reproduction

To reproduce this vulnerability, a privileged user can create a custom script within MaxKB that includes OS command execution. When the script is run, the embedded commands will be executed on the server, demonstrating the remote command execution capability of the vulnerability.

Remediation

Users are advised to update MaxKB to version 1.9.0 or later, where this vulnerability has been fixed.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
10.0
exploitability
6.1
remediation
7.7
relevance
0.0
threat
6.4
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.