CVE-2025-64703: MaxKB has Information Leak in sandbox
Published Nov 13, 2025
·Updated
MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module, although the process run in sandbox. Version 2.3.1 fixes the issue.
Affected Software
2 affected components
MaxKB MaxKB<2.3.1
MaxKB MaxKB<2.3.1
Event History
Nov 13, 2025
CVE Published
via MITRE·03:52 PM
Data Sourced
via MITRE·03:52 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·04:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the severity of CVE-2025-64703?
CVE-2025-64703 has a high severity due to the potential exposure of sensitive information.
2
How do I fix CVE-2025-64703?
To fix CVE-2025-64703, upgrade to MaxKB version 2.3.1 or later.
3
What versions are affected by CVE-2025-64703?
CVE-2025-64703 affects all MaxKB versions prior to 2.3.1.
4
What type of vulnerability is CVE-2025-64703?
CVE-2025-64703 is classified as a sensitive information disclosure vulnerability.
5
Can CVE-2025-64703 be exploited in a sandboxed environment?
Yes, CVE-2025-64703 can be exploited even when the process runs in a sandboxed environment.