CVE-2025-66446High· 8.8▾ TwilightMaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege esca…
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via NVD
Last analysed / modified upstream
0.3%
MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0.
maxkb < 2.4.0Upgrade past the affected range:
maxkb 2.4.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-66419High· 8.8MaxKB is an open-source AI assistant for enterprise
CVE-2025-64511High· 7.4MaxKB is an open-source AI assistant for enterprise
CVE-2025-64703Medium· 6.3MaxKB is an open-source AI assistant for enterprise
CVE-2026-79919Medium· 6.3MaxKB is an open-source AI assistant for enterprise
CVE-2026-79918Medium· 6.3MaxKB is an open-source AI assistant for enterprise
CVE-2026-77519Medium· 5.4MaxKB is an open-source AI assistant for enterprise