CVE-2025-64511 - MaxKB has SSRF in sandbox

CVE ID : CVE-2025-64511
Published : Nov. 13, 2025, 4:15 p.m. | 1 hour, 42 minutes ago
Description : MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool module, although the process runs in a sandbox. Version 2.3.1 fixes the issue.
Severity: 7.4 | HIGH
Visit the link for more details, such as CVSS details, affected products, timeline, and more...

from Latest Vulnerabilities https://ift.tt/6WYRStL

Post a Comment

Previous Post Next Post