---
id: CVE-2025-66419
title: MaxKB is an open-source AI assistant for enterprise
summary: >-
  MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and
  below, the tool module allows an attacker to escape the sandbox environment
  and escalate privileges under certain concurrent conditions. This issue is
  fixed in ve…
severity: high
cvss: 8.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-362
vendor: maxkb
product: maxkb
affected:
  - maxkb < 2.4.0
patched:
  - maxkb 2.4.0
published: '2025-12-11'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T20:10:01.970'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2025-66419'
references:
  - url: >-
      https://github.com/1Panel-dev/MaxKB/commit/f8ada9a110c4dbef8c3c2636c78847ecd621ece7
    label: security-advisories@github.com
  - url: 'https://github.com/1Panel-dev/MaxKB/releases/tag/v2.4.0'
    label: security-advisories@github.com
  - url: >-
      https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f9qm-2pxq-fx6c
    label: security-advisories@github.com
tags:
  - nvd
epss: 0.0031
epssPercentile: 0.21802
ingestedAt: '2026-10-07T20:46:46.867Z'
---

## Overview

MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0.

## Affected

- `maxkb < 2.4.0`

## Remediation

Upgrade past the affected range:

- `maxkb 2.4.0`
