MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can get sensitive informations by Python code in tool module, although the process run in sandbox. Version 2.3.1 fixes the issue.
References
Configurations
No configuration.
History
13 Nov 2025, 16:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-11-13 16:15
Updated : 2025-11-14 16:42
NVD link : CVE-2025-64703
Mitre link : CVE-2025-64703
CVE.ORG link : CVE-2025-64703
JSON object : View
Products Affected
No product.
CWE
CWE-200
Exposure of Sensitive Information to an Unauthorized Actor
