CVE-2025-53928: MaxKB has RCE in MCP call
Published Jul 17, 2025
·Updated
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.
Affected Software
2 affected components
MaxKB MaxKB<1.10.9-lts, <2.0.0
MaxKB MaxKB<1.10.9
Event History
Jul 17, 2025
CVE Published
via MITRE·01:56 PM
Data Sourced
via MITRE·01:56 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·02:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-53928?
CVE-2025-53928 is identified as a Remote Command Execution vulnerability, which is considered a high severity issue.
2
How do I fix CVE-2025-53928?
To fix CVE-2025-53928, upgrade to the latest versions 1.10.9-lts or 2.0.0 of MaxKB.
3
What versions are affected by CVE-2025-53928?
CVE-2025-53928 affects all versions of MaxKB prior to 1.10.9-lts and 2.0.0.
4
Is CVE-2025-53928 a known vulnerability in open-source software?
Yes, CVE-2025-53928 is a documented vulnerability in the open-source MaxKB AI assistant.
5
What kind of vulnerability is CVE-2025-53928?
CVE-2025-53928 is a Remote Command Execution vulnerability, allowing attackers to execute arbitrary commands on the server.