We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-32383

MaxKB has a reverse shell vulnerability in function library



Description

MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability allow privileged‌ users to create a reverse shell. This vulnerability is fixed in v1.10.4-lts.

Reserved 2025-04-06 | Published 2025-04-10 | Updated 2025-04-10 | Assigner GitHub_M


MEDIUM: 4.3CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L

Problem types

CWE-94: Improper Control of Generation of Code ('Code Injection')

Product status

< 1.10.4-lts
affected

References

github.com/.../MaxKB/security/advisories/GHSA-fjf6-6cvf-xr72

github.com/...ommit/4ae02c8d3eb65542c88ef58c0abd94c52c949d8f

cve.org (CVE-2025-32383)

nvd.nist.gov (CVE-2025-32383)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-32383

Support options

Helpdesk Chat, Email, Knowledgebase