CVE-2025-64511

7.4

1Panel-dev · MaxKB

A Server-Side Request Forgery vulnerability in MaxKB allows authenticated users to access internal network services via the tool module.

Executive summary

A Server-Side Request Forgery vulnerability in MaxKB versions prior to 2.3.1 could allow an authenticated attacker to access internal network resources.

Vulnerability

This vulnerability is a Server-Side Request Forgery (CWE-918) flaw occurring within the tool module. It allows an authenticated user to bypass sandbox restrictions and interact with internal network services, such as databases.

Business impact

The ability to perform Server-Side Request Forgery poses a significant risk to internal infrastructure by allowing attackers to probe and interact with non-public services. With a CVSS score of 7.4, this high-severity issue could lead to unauthorized data access or the compromise of internal backend systems that are otherwise shielded from the internet.

Remediation

Immediate Action: Update MaxKB to version 2.3.1 or later immediately to apply the vendor-provided patch.

Proactive Monitoring: Review application access logs for unusual outbound requests originating from the MaxKB server, particularly those targeting internal IP ranges or sensitive ports.

Compensating Controls: Implement strict network egress filtering on the host running MaxKB to prevent the application from communicating with unauthorized internal network segments.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

The vulnerability presents a clear risk to internal network security by enabling unauthorized access to backend services. Organizations utilizing MaxKB should prioritize the upgrade to version 2.3.1 to resolve the flaw. If an immediate update is not feasible, restrict the network reachability of the MaxKB instance to essential services only.

More 1Panel-dev CVEs

Sources