MaxKB
Security Risk Profile
Security Risk Score
Comprehensive risk assessment based on 34 vulnerabilities, EPSS scores, exploitation status, and remediation availability.
📅 Data spans from January 2, 2025 to present
Threat Assessment
Severity Distribution
Exploit Likelihood
Age Distribution
Common Weaknesses (CWE)
Most Affected Products
Recent Vulnerabilities
See more →MaxKB function-library sandbox escape: dlopen stack-check bypass via importlib meta-path callbacks and unhooked dlsym(RTLD_NEXT)
MaxKB cross-knowledge IDOR lets a normal user read and modify documents and paragraphs in another knowledge base
MaxKB: Missing per-tool authorization in the agent and workflow tool-dispatch path
MaxKB: Management chat-record routes trust path application_id but load ChatRecord by global chat_id
MaxKB: Known MCP tool IDs expose owner Tool.code and can be referenced by attacker workflows
MaxKB: Homepage ranking leaks application IDs that workflow application-nodes can use to invoke another user's application
MaxKB: Expired application API keys remain usable on `/chat/api/mcp`
MaxKB: UpdateStoreTool fetches caller-supplied app-store URLs without host validation
MaxKB: SSRF Bypass via DNS Rebinding in MaxKB OSS URL Fetch
MaxKB: Broken Access Control in MaxKB OSS URL Fetch API
Monitor MaxKB in Real-Time
Get instant alerts when new vulnerabilities are discovered. Stay ahead of security threats with SecAlerts.