Impact
UpdateStoreTool allows an authenticated workspace user to provide arbitrary download URLs and callbacks to requests.get without validating the host or restricting redirects, creating a Server‑Side Request Forgery weakness identified by CWE‑918. This flaw can be leveraged to cause the MaxKB server to request internal, loopback, link‑local, or cloud‑metadata addresses, potentially exposing sensitive internal resources or facilitating privilege escalation. The direct impact is the unauthorized disclosure of internal data or assistance in other attacks that rely on making the server reach otherwise inaccessible endpoints.
Affected Systems
1Panel‑dev MaxKB versions 2.0.0 through 2.10.4‑lts are affected. No other vendors or products are listed.
Risk and Exploitability
The CVSS score of 5.3 indicates moderate severity, and the vulnerability is not currently listed in CISA KEV. An EPSS score of 0.00215 indicates a very low exploitation probability. The attack requires an authenticated workspace user with permission to run the UpdateStoreTool, after which the attacker can supply malicious URLs to trick the server into making internal HTTP requests. A fix has been merged into the v2 branch but has not yet been released to users, so attack remains exploitable until a patched version is deployed.
OpenCVE Enrichment