๐Ÿ” CVE Alert

CVE-2026-79917

MEDIUM 6.5

MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_user_id or to the application bound to the caller's token. An attacker with any chat token and a known victim chat_id can create an unauthenticated public ChatShareLink exposing the victim's conversation and can create PublicFileAccess state that makes associated files retrievable without credentials, with no available revoke path. No fixed version is available as of this review.

CWE CWE-285 CWE-639
Vendor 1panel-dev
Product maxkb
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for 1panel-dev maxkb

Be the first to know when new medium vulnerabilities affecting 1panel-dev maxkb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N
Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
Low
Availability
None

Affected Versions

1Panel-dev / MaxKB
>= 2.7.0, <= 2.10.4-lts

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-m8gr-554p-8r82