CVE 4.6 MEDIUM

MaxKB sandbox bypass_CVE-2025-53927

4.6 / 10
MEDIUM
CVSS:3.1/AV:N/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:L

Description

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use the `shutil.copy2` method in Python to copy the command they want to execute to the executable directory. This bypasses directory restrictions and reverse shell. Version 2.0.0 fixes the issue.

Basic Information

ID CVE-2025-53927
Source GitHub_M
Published Jul 17, 2025 at 13:50
Modified Jul 17, 2025 at 19:56

Affected Product

Vendor 1Panel-dev
Product MaxKB
Version < 2.0.0
Affected Versions 1Panel-dev MaxKB < 2.0.0

CWE Classification

References

💭 Join the Security Discussion

🔒 Your email address will not be published. Required fields are marked *

⚠️ Please be respectful and constructive in your comments. Security discussions should remain professional.