CVE-2025-64511: MaxKB has SSRF in sandbox
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool module, although the process runs in a sandbox. Version 2.3.1 fixes the issue.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2025-64511?
CVE-2025-64511 is considered a high severity vulnerability due to unauthorized access to internal network services.
How do I fix CVE-2025-64511?
To remediate CVE-2025-64511, upgrade to MaxKB version 2.3.1 or later.
What impact does CVE-2025-64511 have on security?
CVE-2025-64511 can allow attackers to access sensitive internal database services, posing a significant risk to data security.
Is CVE-2025-64511 present in all versions of MaxKB?
Yes, CVE-2025-64511 affects all versions of MaxKB prior to version 2.3.1.
What specific vulnerability does CVE-2025-64511 exploit?
CVE-2025-64511 exploits a flaw in the tool module that allows access to internal network services via Python code in a sandboxed environment.