{"id":"CVE-2026-77517","published":"2026-09-21T21:17:10.317","lastModified":"2026-09-21T21:17:10.440","description":"MaxKB is an open-source AI assistant for enterprise. From version 2.0.0 through 2.10.2-lts, document and paragraph operate routes authorize only knowledge_id in the request path, then query the target Document by document_id or Paragraph by paragraph_id without confirming that the object belongs to that knowledge base. A normal workspace user with a known victim document or paragraph UUID can use an attacker-owned knowledge-base path to read or modify content in another user's knowledge base. No fixed version is available as of this review.","cvssScore":5.4,"cvssSeverity":"MEDIUM","cvssVector":"CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:N","cwes":["CWE-639","CWE-862"],"vendors":[],"products":[],"references":[{"url":"https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-58cm-c5jq-96vf","tags":[]}],"exploitRefs":[{"url":"https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-58cm-c5jq-96vf","tags":[]}],"hasPoc":true,"ai":{"summary":"The flaw allows a workspace user to read or modify content in another user's knowledge base by exploiting improperly authorized document and paragraph routes. This matters because it breaches data isolation and confidentiality.","exploitability":"Exploitation is moderately easy if an attacker has access to the victim’s UUID, as no fixed version addresses the issue.","blast_radius":"If exploited, this could lead to significant data leakage or unauthorized modifications across multiple knowledge bases within the system.","remediation":"Implement proper authorization checks to ensure that only relevant users can access and modify content in their respective knowledge bases.","tags":["auth-bypass","web","data-leakage","api-security"],"model":"qwen2.5:7b-instruct","analyzedAt":"2026-09-22T06:26:29.984Z"}}