CVE-2026-39418: MaxKB: SSRF via sandbox network hook bypass

Published Apr 14, 2026
·
Updated

MaxKB is an open-source AI assistant for enterprise. In versions 2.7.1 and below, sandbox network protection can be bypassed by using socket.sendto() with the MSGFASTOPEN flag. This allows authenticated user with tool-editing permissions to reach internal services that are explicitly blocked by the sandbox's banned hosts configuration. MaxKB's sandbox uses LDPRELOAD to hook the connect() function and block connections to banned IPs, but Linux's sendto() with the MSGFASTOPEN flag can establish TCP connections directly through the kernel without ever calling connect(), completely bypassing the IP validation. Although sendto is listed in the syscall() wrapper, this is ineffective because glibc invokes the kernel syscall directly rather than routing through the hooked syscall() function. This issue has been fixed in version 2.8.0.

Affected Software

2 affected components
MaxKB MaxKB<=2.7.1
MaxKB MaxKB<2.8.0

Event History

Apr 14, 2026
CVE Published
via MITRE·12:08 AM
Data Sourced
via MITRE·12:08 AM
DescriptionSeverityWeakness
Data Sourced
via NVD·01:16 AM
RemedyDescriptionSeverityWeaknessAffected Software
Nov 9, 58271
Event
via NVD·06:09 PM
Free Weekly Intel

Don't miss critical vulnerabilities

Join thousands of security professionals who receive our weekly digest of trending CVEs, zero-days, and exploited vulnerabilities.

No spam. Unsubscribe anytime.

Frequently Asked Questions

1

What is the severity of CVE-2026-39418?

CVE-2026-39418 is considered a high severity vulnerability due to its potential for unauthorized access to internal resources.

2

How do I fix CVE-2026-39418?

To fix CVE-2026-39418, upgrade MaxKB to version 2.8.0 or later, which addresses the sandbox network hook bypass.

3

Who is affected by CVE-2026-39418?

All users of MaxKB versions 2.7.1 and below with tool-editing permissions are affected by CVE-2026-39418.

4

What can happen if CVE-2026-39418 is exploited?

If exploited, CVE-2026-39418 allows an authenticated user to access internal systems, risking data confidentiality.

5

What is the cause of CVE-2026-39418?

CVE-2026-39418 is caused by a bypass of the sandbox network protection due to the improper handling of the socket.sendto() method with the MSG_FASTOPEN flag.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203