CVE-2026-79919

medium

Description

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack heuristic sees a Python import frame, then use unhooked dlsym with RTLD_NEXT to resolve glibc's real syscall and bypass the sandbox syscall blacklist. An authenticated workspace member can consequently read or write files, execute processes, or access networks as the sandbox user. This issue is fixed in version 2.10.6-lts.

References

https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-6h35-c779-4v37

https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.6-lts

https://github.com/1Panel-dev/MaxKB/commit/d4bd22af8ba14a9dea317f9034332fec4e964697

Details

Source: Mitre, NVD

Published: 2026-09-21

Updated: 2026-09-22

Risk Information

CVSS v2

Base Score: 6.5

Vector: CVSS2#AV:N/AC:L/Au:S/C:P/I:P/A:P

Severity: Medium

CVSS v3

Base Score: 6.3

Vector: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Severity: Medium

EPSS

EPSS: 0.00282