๐Ÿ” CVE Alert

CVE-2026-79919

MEDIUM 6.3

MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)

CVSS Score
6.3
EPSS Score
0.0%
EPSS Percentile
0th

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack heuristic sees a Python import frame, then use unhooked dlsym with RTLD_NEXT to resolve glibc's real syscall and bypass the sandbox syscall blacklist. An authenticated workspace member can consequently read or write files, execute processes, or access networks as the sandbox user. This issue is fixed in version 2.10.6-lts.

CWE CWE-693
Vendor 1panel-dev
Product maxkb
Published Sep 21, 2026
Stay Ahead of the Next One

Get instant alerts for 1panel-dev maxkb

Be the first to know when new medium vulnerabilities affecting 1panel-dev maxkb are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

1Panel-dev / MaxKB
< 2.10.6-lts

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-6h35-c779-4v37 github.com: https://github.com/1Panel-dev/MaxKB/commit/d4bd22af8ba14a9dea317f9034332fec4e964697 github.com: https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.6-lts