CVE-2026-39423: Stored XSS via Eval Injection in EchartsRander Component
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting with the AI chat interface to execute arbitrary JavaScript in the browsers of other users, including administrators, resulting in Stored Cross-Site Scripting (XSS). This issue has been fixed in version 2.8.0.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2026-39423?
CVE-2026-39423 is classified as a critical vulnerability due to its potential for remote code execution via Eval Injection.
How do I fix CVE-2026-39423?
To mitigate CVE-2026-39423, upgrade MaxKB to version 2.8.0 or later where the vulnerability has been patched.
What components are affected by CVE-2026-39423?
CVE-2026-39423 specifically affects the EchartsRander Component in MaxKB versions 2.7.1 and below.
Who is impacted by CVE-2026-39423?
Anyone using MaxKB version 2.7.1 or earlier is at risk from CVE-2026-39423 due to the stored XSS vulnerability.
What exploits are possible with CVE-2026-39423?
CVE-2026-39423 allows attackers to execute arbitrary JavaScript in the context of users interacting with the AI chat interface.