MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool module, although the process runs in a sandbox. Version 2.3.1 fixes the issue.
References
Configurations
No configuration.
History
13 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-13 16:15
Updated : 2025-11-14 16:42
NVD link : CVE-2025-64511
Mitre link : CVE-2025-64511
CVE.ORG link : CVE-2025-64511
JSON object : View
Products Affected
No product.
CWE
CWE-918
Server-Side Request Forgery (SSRF)
