CVE-2026-77522
MaxKB: Authenticated full-read SSRF via the knowledge web-document import/sync crawler (Fork.fork requests.get, no internal-IP guard, non-blind)
CVSS Score
4.3
EPSS Score
0.0%
EPSS Percentile
0th
MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get with verify=False and without restricting schemes, loopback, link-local, private, or reserved addresses. The response body is converted into imported document content, allowing a low-privileged user to read cloud metadata or internal HTTP services through the MaxKB server. No fixed version is available as of this review.
| CWE | CWE-918 |
| Vendor | 1panel-dev |
| Product | maxkb |
| Published | Sep 21, 2026 |
Stay Ahead of the Next One
Get instant alerts for 1panel-dev maxkb
Be the first to know when new medium vulnerabilities affecting 1panel-dev maxkb are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None
Affected Versions
1Panel-dev / MaxKB
<= 2.10.3-lts