External risk intelligence

MaxKB Command Execution Vulnerability

CVE advisorySeverity: CRITICAL (CVSS 10.0)

CVE-2026-77521

MaxKB is an AI assistant application designed for enterprise deployment. As a web-based assistant service, it is typically deployed as a user-facing web application or API service, making it commonly reachable from the internet or internal networks for interaction by end users.

OS Command Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

This vulnerability affects the MaxKB open-source AI assistant, specifically impacting its ability to securely execute commands. Malicious actors could potentially exploit this to run unauthorized commands on affected systems, leading to compromised data or system control. The main concern at this stage is confirming if your organization utilizes this specific AI assistant and, if so, assessing the potential exposure.

  • AI assistant can run unauthorized commands.
  • Confirm relevance and exposure of this AI assistant.
  • Understand potential for unauthorized command execution.

Attack Path

How an attacker could exploit the issue

An attacker could initiate a command execution attack by sending untrusted chat or ingested content to the MaxKB AI assistant. This content would be processed by a vulnerable component that bypasses necessary approval checks, allowing commands to be run without human intervention. The consequences of this vulnerability include the potential for significant system compromise.

  • No special access needed.
  • Untrusted content triggers execution.
  • Risk of unauthorized command execution.

Live Threat

Current exploitation, exposure, and threat context

When supported by the advisory, untrusted input could lead to unauthorized command execution on the affected system, potentially allowing an attacker to compromise the application's integrity, confidentiality, and availability. This occurs when the assistant's shell backend is not configured to require human approval for executing commands.

  • System commands on the application user.
  • Untrusted input may trigger execution.
  • Command execution could impact service.

Operational Fix

Recommended remediation, mitigation, and detection steps

This critical vulnerability in MaxKB, an open-source AI assistant, allows for command execution through untrusted input. Teams responsible for application deployments, infrastructure, and security should collaborate to identify affected instances, assess business criticality and exposure, and coordinate remediation. The first practical step involves discovering all MaxKB deployments, verifying their reachability, confirming their owners, and then prioritizing fixes based on risk and operational impact.

  • Application and Infrastructure teams own the issue.
  • Verify MaxKB instances and their reachability.
  • Plan remediation based on asset criticality.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is MaxKB?

MaxKB is an open-source AI assistant platform built for enterprise environments. It helps organizations integrate AI capabilities by providing tools, skills, and sub-applications that interact with user-provided content. Users deploy it to automate tasks and manage ingested data through a chat-based interface.

What is the vulnerability in CVE-2026-77521?

This vulnerability is an OS Command Injection (CWE-78). It happens when the software's backend erroneously allows unauthorized commands to run without the required human approval. Because the system fails to properly restrict or validate input, an attacker can manipulate the assistant to execute arbitrary system-level commands.

How can an attacker trigger this command execution?

An attacker triggers this by sending specially crafted, untrusted chat messages or ingested content to the AI assistant. The vulnerability is specifically tied to the SandboxShellBackend; if an instance is not configured to use this backend or if the assistant lacks access to the execute tool, it does not trigger the bug.

Is my MaxKB instance at risk according to Halo Surface Signal?

Halo Surface Signal identifies MaxKB as an application typically deployed as a user-facing web service. Because it is designed to be interacted with by end users, it is often reachable via the internet or internal networks, increasing the likelihood that it is accessible to potential attackers.

What should I do to address this vulnerability?

The primary response is to update your MaxKB deployment to version 2.10.5-lts or higher, which contains the fix. First, discover all instances of MaxKB within your infrastructure, confirm their current version, and assess their network reachability to prioritize patching the most exposed systems.

References