---
id: CVE-2026-79918
title: MaxKB is an open-source AI assistant for enterprise
summary: >-
  MaxKB is an open-source AI assistant for enterprise. Prior to version
  2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and
  execveat to prevent subprocess creation but does not hook fexecve. An
  authenticated attacker…
severity: medium
cvss: 6.3
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L'
cwe:
  - CWE-693
vendor: 1Panel-dev
product: MaxKB
affected:
  - MaxKB < 2.10.6-lts
published: '2026-09-21'
updated: '2026-09-24'
sourceUpdated: '2026-09-24T23:19:09.383'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-79918'
references:
  - url: >-
      https://github.com/1Panel-dev/MaxKB/commit/6fa7947a85030b87977c4026f33af11ca10dd1e6
    label: security-advisories@github.com
  - url: 'https://github.com/1Panel-dev/MaxKB/releases/tag/v2.10.6-lts'
    label: security-advisories@github.com
  - url: >-
      https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-9mh9-v949-fwqh
    label: security-advisories@github.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-09-24T22:45:51.318278Z'
epss: 0.00362
epssPercentile: 0.27403
ingestedAt: '2026-09-21T21:53:57.420Z'
---

## Overview

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
