๐Ÿ” CVE Alert

CVE-2026-6108

MEDIUM 6.3

1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection

CVSS Score
6.3
EPSS Score
0.2%
EPSS Percentile
42th

A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Model Context Protocol Node. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.

CWE CWE-78 CWE-77
Vendor 1panel-dev
Product maxkb
Published Apr 12, 2026
Last Updated Apr 14, 2026
Stay Ahead of the Next One

Get instant alerts for 1panel-dev maxkb

Be the first to know when new medium vulnerabilities affecting 1panel-dev maxkb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L/E:P/RL:O/RC:C
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality
Integrity
Availability

Affected Versions

1Panel-dev / MaxKB
2.6.0 2.6.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
vuldb.com: https://vuldb.com/vuln/356968 vuldb.com: https://vuldb.com/vuln/356968/cti vuldb.com: https://vuldb.com/submit/782279 github.com: https://github.com/AnalogyC0de/public_exp/issues/30

Credits

๐Ÿ” Ana10gy (VulDB User) VulDB CNA Team