CVE-2025-32383: MaxKB has a reverse shell vulnerability in function library
MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability allow privileged users to create a reverse shell. This vulnerability is fixed in v1.10.4-lts.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-32383?
CVE-2025-32383 is considered a critical vulnerability due to its potential to allow unauthorized reverse shell access.
How do I fix CVE-2025-32383?
To remediate CVE-2025-32383, update to the latest version of Max Knowledge Base beyond 1.10.4-lts.
What type of vulnerability is CVE-2025-32383?
CVE-2025-32383 is a reverse shell vulnerability that affects the function library module of Max Knowledge Base.
Who is affected by CVE-2025-32383?
CVE-2025-32383 affects users of Max Knowledge Base versions up to 1.10.4-lts.
Can CVE-2025-32383 be exploited remotely?
Yes, CVE-2025-32383 can be exploited remotely by an attacker with privileged user access.