CVE-2026-45412: MaxKB: Unauthenticated SSRF via Workflow Template Import
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via workflowtemplate Import. Authenticated users can supply arbitrary URLs in workflowtemplate.downloadUrl which are fetched server-side without any URL validation or internal IP filtering. This vulnerability is fixed in 2.9.1.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
MaxKBto a version that resolves this vulnerability.Fixed in 2.9.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-45412?
CVE-2026-45412 has a risk rating of 57, indicating a moderate severity level.
How do I fix CVE-2026-45412?
To fix CVE-2026-45412, upgrade MaxKB to version 2.9.1 or later.
What type of vulnerability is CVE-2026-45412?
CVE-2026-45412 is classified as a Server-Side Request Forgery (SSRF) vulnerability.
Who is affected by CVE-2026-45412?
Authenticated users of MaxKB prior to version 2.9.1 are affected by CVE-2026-45412.
What does CVE-2026-45412 allow an attacker to do?
CVE-2026-45412 allows authenticated users to supply arbitrary URLs that are fetched server-side, potentially exposing internal resources.