CVE-2025-66419: MaxKB vulnerable to privilege escalation through sandbox bypass
MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2025-66419?
CVE-2025-66419 is considered a critical vulnerability due to its potential to escalate privileges by escaping a sandbox environment.
How do I fix CVE-2025-66419?
To fix CVE-2025-66419, upgrade MaxKB to version 2.4.0 or later, where the issue has been resolved.
What versions are affected by CVE-2025-66419?
CVE-2025-66419 affects MaxKB versions 2.3.1 and below.
What impact does CVE-2025-66419 have on enterprise environments?
CVE-2025-66419 can allow attackers to gain elevated privileges, potentially compromising the security of enterprise systems.
Is CVE-2025-66419 specific to any operating systems?
CVE-2025-66419 is not tied to specific operating systems, but rather to the MaxKB software itself and its versions.