Skip to main content
Vulnerability Database/CVE-2026-77521

CVE-2026-77521: MaxKB AI Assistant RCE Vulnerability

CVE-2026-77521 is a remote code execution vulnerability in MaxKB AI Assistant that allows untrusted content to execute shell commands without human approval. This article covers technical details, affected versions, and mitigation.

Published:

CVE-2026-77521 Overview

MaxKB is an open-source AI assistant platform for enterprise deployments. Versions prior to 2.10.5-lts contain a command injection flaw in SandboxShellBackend that exposes an execute shell tool to assistants without human approval. Untrusted chat input or ingested content can trigger arbitrary command execution on the host. Source deployments with MAXKB_SANDBOX disabled run commands directly as the application user. Official root container deployments are also affected because the string-based gosu wrapper allowed shell metacharacters to escape the intended sandbox boundary. The issue is tracked under [CWE-78] (OS Command Injection).

Critical Impact

Unauthenticated network attackers can achieve remote command execution on MaxKB hosts, including full command execution as root inside official container deployments.

Affected Products

  • MaxKB versions prior to 2.10.5-lts
  • MaxKB source deployments with MAXKB_SANDBOX disabled
  • Official MaxKB root container images using the string-based gosu wrapper

Discovery Timeline

  • 2026-09-21 - CVE-2026-77521 published to NVD
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-77521

Vulnerability Analysis

MaxKB assistants can be configured with tools, MCP tools, skills, or sub-applications that route through SandboxShellBackend. This backend exposes an execute shell tool to the assistant runtime. The tool is not excluded from the assistant tool surface, and execute is omitted from the interrupt_on list. As a result, the platform never prompts a human operator to approve shell execution requests. Any content the assistant processes, including untrusted chat messages or ingested knowledge base entries, can drive the assistant to invoke execute with attacker-controlled arguments. Attackers can weaponize prompt injection or malicious document ingestion to execute operating system commands on the MaxKB host.

Root Cause

The root cause is missing input sanitization combined with missing authorization controls around a privileged tool. The SandboxShellBackend implementation registers execute as an assistant-callable tool without adding it to the interrupt list that enforces human-in-the-loop approval. In parallel, the official container image invokes gosu through a string-based shell wrapper, so shell metacharacters in tool arguments are interpreted by the shell rather than passed as literal arguments. This breaks the sandbox boundary and allows commands to execute in the root container context. Refer to the GitHub Security Advisory GHSA-f36j-f34j-h3rx for the maintainer analysis.

Attack Vector

Exploitation requires only network access to a MaxKB instance that exposes a vulnerable assistant. An attacker submits a crafted chat prompt or plants malicious content in a data source consumed by the assistant. The assistant invokes the execute shell tool with attacker-controlled input. On source deployments with MAXKB_SANDBOX disabled, the command runs as the MaxKB application user. On official container deployments, shell metacharacters break out of the gosu wrapper and execute as root inside the container. The fix commit is available at GitHub Commit 594f50f.

Detection Methods for CVE-2026-77521

Indicators of Compromise

  • Unexpected child processes of the MaxKB application process, particularly /bin/sh, bash, curl, wget, or python invocations spawned from assistant workers.
  • Outbound network connections from MaxKB containers to unfamiliar hosts following user chat activity.
  • New files, cron entries, or SSH keys written by the MaxKB application user or root inside the container.
  • Assistant audit entries showing execute tool invocations without corresponding human approval events.

Detection Strategies

  • Inventory all MaxKB deployments and identify instances running versions below 2.10.5-lts.
  • Review assistant configurations for tools, MCP tools, skills, or sub-applications that reference SandboxShellBackend.
  • Correlate assistant tool invocation logs with process creation telemetry on the underlying host or container.
  • Alert on shell metacharacters (;, &&, |, backticks, $()) appearing in tool arguments captured by application logs.

Monitoring Recommendations

  • Forward MaxKB application logs and container process telemetry to a centralized analytics platform for correlation.
  • Monitor egress traffic from MaxKB hosts and flag connections that deviate from baseline model provider and dependency endpoints.
  • Track file integrity for the MaxKB installation directory and container filesystem to catch payload drops.

How to Mitigate CVE-2026-77521

Immediate Actions Required

  • Upgrade MaxKB to version 2.10.5-lts or later using the v2.10.5-lts release.
  • Restrict network exposure of MaxKB instances to trusted users and networks until the upgrade is complete.
  • Audit existing assistants and remove or disable any that expose SandboxShellBackend tools, MCP tools, skills, or sub-applications.
  • Rotate credentials, API keys, and tokens stored on or accessible to MaxKB hosts if exploitation cannot be ruled out.

Patch Information

The maintainers fixed the flaw in MaxKB 2.10.5-lts. The patch excludes the execute shell tool from the default assistant tool surface and adds execute to interrupt_on so human approval is required. The container gosu invocation was also refactored to avoid string-based shell interpretation. Details are available in the fix commit.

Workarounds

  • Disable any assistants that use SandboxShellBackend-backed tools, MCP tools, skills, or sub-applications until patching is possible.
  • Enable MAXKB_SANDBOX on source deployments to prevent commands from executing directly as the application user.
  • Place MaxKB behind an authenticating reverse proxy and restrict inbound access to vetted operators.
  • Run MaxKB containers as a non-root user and drop unnecessary Linux capabilities to limit blast radius.

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.