MaxKB Improper File Permissions Vulnerability Allowing Privilege Escalation
Vulnerability
A vulnerability in MaxKB, an open-source AI assistant for enterprise, exists in versions through 2.3.1. The issue stems from improper file permissions that enable attackers to overwrite critical files, including the built-in dynamic linker. This flaw could lead to privilege escalation.
Impact
Exploitation of this vulnerability could result in unauthorized privilege escalation.
Remediation
Users can upgrade to MaxKB version 2.4.0 to address this vulnerability.
Added: Dec 11, 2025, 10:19 PM
Updated: Dec 11, 2025, 10:19 PM
Vulnerability Rating
Custom Algorithm
spread
0.0impact
10.0exploitability
3.3remediation
7.7relevance
1.3threat
0.0urgency
2.9incentive
1.7Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
