Skip to main content
CRITICAL

CVE-2026-77521

CVSS v3

10

CRITICAL

EPSS Score

1.0 %

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_SANDBOX disabled run commands directly as the application user, while the official root container's

Technical details

CVSS v3 Vector
3.1
Published
2026-09-21
Last Modified
2026-09-22

Frequently asked questions

What is CVE-2026-77521?

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.5-lts, assistants with a tool, MCP tool, skill, or sub-application use SandboxShellBackend, which exposes an execute shell tool without excluding it and omits execute from interrupt_on, so human approval is not required. Untrusted chat or ingested content can therefore cause command execution; source deployments with MAXKB_SANDBOX disabled run commands directly as the application user, while the official root container's

Is CVE-2026-77521 actively exploited?

Active exploitation of CVE-2026-77521 has not been confirmed. The EPSS score is 1.0%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2026-77521?

CVE-2026-77521 has a CVSS v3 base score of 10 (CRITICAL severity), with vector string 3.1.

Is CVE-2026-77521 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key