Impact
The vulnerability exists in the tool import feature and MCP referencing mode of MaxKB; it allows an authenticated user to upload a .tool file that contains a stdio transport with malicious payloads. When processed by the AI Chat node, the flaw causes MultiServerMCPClient to execute the payload, granting the attacker the ability to run arbitrary system commands with the privileges of the MaxKB service. This is a Command Injection weakness (CWE‑78).
Affected Systems
The product affected is MaxKB from 1Panel‑dev. All releases prior to version 2.10.0‑lts are vulnerable. The issue was fixed in the 2.10.0‑lts release.
Risk and Exploitability
The CVSS score of 8.8 classifies the vulnerability as high severity, while the EPSS score of less than 1% indicates a low likelihood of widespread exploitation. It is not listed in the CISA KEV catalog. Exploitation requires authentication to the application; the attacker must successfully upload a crafted .tool file and trigger its execution through the AI Chat node to achieve remote code execution on the host running MaxKB. The likely attack vector is via the web interface used for tool import and chat interaction.
OpenCVE Enrichment