CVE Database
/

CVE-2025-48950

Back to search

CVE-2025-48950

Published: Jun 3, 2025

Modified: Jun 3, 2025

PUBLISHED

Description

MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as `/bin,/usr/bin`, etc. Therefore, attackers can exploit some files with execution permissions in non blacklisted directories to carry out attacks. Version 1.10.8-lts fixes the issue.

VendorProductVersions

1Panel-dev

MaxKB

affected
< 1.10.8-lts

Weaknesses (CWE)

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now