CVE-2026-77521

10.0

1Panel-dev · MaxKB

MaxKB contains an OS command injection vulnerability in SandboxShellBackend that allows unauthenticated attackers to achieve remote code execution via untrusted chat or ingested content.

Executive summary

A critical OS command injection vulnerability in MaxKB allows unauthenticated remote attackers to execute arbitrary commands with the privileges of the application user.

Vulnerability

This vulnerability stems from the SandboxShellBackend component, which fails to properly neutralize special elements used in OS commands and omits necessary human approval for execution tasks. An unauthenticated attacker can supply malicious input through chat or ingested content to trigger command execution outside the intended sandbox environment.

Business impact

The potential for unauthenticated remote code execution poses a catastrophic risk to the integrity, confidentiality, and availability of the host system. Given the CVSS score of 10.0, this flaw effectively grants an attacker full control over the application environment, which could lead to total data compromise, unauthorized lateral movement within the network, and complete service disruption.

Remediation

Immediate Action: Update 1Panel-dev MaxKB to version 2.10.5-lts or later immediately to apply the required security patches.

Proactive Monitoring: Monitor application logs for unexpected shell command execution patterns or unauthorized requests directed at chat and ingestion endpoints.

Compensating Controls: Implement strict network segmentation and egress filtering to limit the potential reach of an attacker if code execution is achieved, and utilize a Web Application Firewall to inspect and block suspicious payloads in chat inputs.

Exploitation status

Public Exploit Available: No — there is no confirmed public exploit in the available data.

Analyst recommendation

The severity of this vulnerability cannot be overstated given the reach of unauthenticated remote code execution. Organizations running MaxKB must prioritize the update to version 2.10.5-lts as their primary security objective to neutralize this critical risk. Failure to patch will leave the infrastructure exposed to complete takeover by remote adversaries.

More 1Panel-dev CVEs

History

  1. Disclosed CVE record published
  2. Collected by CVE Brief via github
  3. Analyst report written
  4. Published in the daily brief critical section

Sources