CVE-2026-6107: 1Panel-dev MaxKB ChatHeadersMiddleware chat_headers_middleware.py cross site scripting
A flaw has been found in 1Panel-dev MaxKB up to 2.6.1. This issue affects some unknown processing of the file apps/common/middleware/chatheadersmiddleware.py of the component ChatHeadersMiddleware. This manipulation of the argument Name causes cross site scripting. Remote exploitation of the attack is possible. Upgrading to version 2.8.0 is capable of addressing this issue. Patch name: 026a2d623e2aa5efa67c4834651e79d5d7cab1da. Upgrading the affected component is advised. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
1Panel-dev MaxKB ChatHeadersMiddlewareto a version that resolves this vulnerability.Fixed in 2.8.0Patch 026a2d623e2aa5efa67c4834651e79d5d7cab1da
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6107?
CVE-2026-6107 has a moderate severity due to its potential for cross-site scripting attacks.
How do I fix CVE-2026-6107?
To fix CVE-2026-6107, upgrade to a version of 1Panel-dev MaxKB beyond 2.6.1.
What component is affected by CVE-2026-6107?
CVE-2026-6107 affects the ChatHeadersMiddleware component in chat_headers_middleware.py.
What versions of 1Panel-dev MaxKB are affected by CVE-2026-6107?
CVE-2026-6107 affects all versions of 1Panel-dev MaxKB up to and including version 2.6.1.
Can CVE-2026-6107 lead to data breaches?
Yes, CVE-2026-6107 can potentially allow attackers to execute scripts in the user's browser, leading to data breaches.