MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). Prior to version 1.9.0, a remote command execution vulnerability exists in the module of function library. The vulnerability allow privileged‌ users to execute OS command in custom scripts. The vulnerability has been fixed in v1.9.0.
History

Fri, 01 Aug 2025 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Maxkb
Maxkb maxkb
CPEs cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:*
Vendors & Products Maxkb
Maxkb maxkb

Thu, 02 Jan 2025 18:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 02 Jan 2025 14:45:00 +0000

Type Values Removed Values Added
Description MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). Prior to version 1.9.0, a remote command execution vulnerability exists in the module of function library. The vulnerability allow privileged‌ users to execute OS command in custom scripts. The vulnerability has been fixed in v1.9.0.
Title MaxKB RCE vulnerability in function library
Weaknesses CWE-78
References
Metrics cvssV3_1

{'score': 6.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published: 2025-01-02T14:26:19.958Z

Updated: 2025-01-02T17:56:52.607Z

Reserved: 2024-12-16T17:30:30.068Z

Link: CVE-2024-56137

cve-icon Vulnrichment

Updated: 2025-01-02T17:56:44.444Z

cve-icon NVD

Status : Analyzed

Published: 2025-01-02T15:15:24.283

Modified: 2025-08-01T20:15:27.940

Link: CVE-2024-56137

cve-icon Redhat

No data.