CVE-2025-48950: MaxKB Python Sandbox Bypass in Function Library
MaxKB is an open-source AI assistant for enterprise. Prior to version 1.10.8-lts, Sandbox only restricts the execution permissions of binary files in common directories, such as /bin,/usr/bin, etc. Therefore, attackers can exploit some files with execution permissions in non blacklisted directories to carry out attacks. Version 1.10.8-lts fixes the issue.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-48950?
CVE-2025-48950 is classified as a high-severity vulnerability due to its potential to allow unauthorized execution of files.
How do I fix CVE-2025-48950?
To fix CVE-2025-48950, upgrade to version 1.10.8-lts or later of MaxKB to ensure proper execution permissions are enforced.
What type of systems are affected by CVE-2025-48950?
CVE-2025-48950 affects MaxKB versions prior to 1.10.8-lts in enterprise environments where the software is deployed.
What can attackers do with CVE-2025-48950?
With CVE-2025-48950, attackers can potentially execute malicious files that are granted improper permissions in non-standard directories.
Is user data at risk due to CVE-2025-48950?
Yes, user data may be at risk if an attacker exploits CVE-2025-48950 to execute unauthorized actions on affected systems.