CVE-2026-79917

Source
https://cve.org/CVERecord?id=CVE-2026-79917
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79917.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79917
Aliases
  • GHSA-m8gr-554p-8r82
Published
2026-09-21T20:43:27Z
Modified
2026-09-24T03:30:25Z
Severity
  • 6.5 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:L/A:N CVSS Calculator
Summary
MaxKB: Chat share-link endpoint missing owner check: a chat token can publish another user's conversation
Details

MaxKB is an open-source AI assistant for enterprise. In 2.7.0 through 2.10.4-lts, POST /chat/api/{application_id}/chat/{chat_id}/share_chat verifies that a conversation exists but does not verify that it belongs to the authenticated chat_user_id or to the application bound to the caller's token. An attacker with any chat token and a known victim chat_id can create an unauthenticated public ChatShareLink exposing the victim's conversation and can create PublicFileAccess state that makes associated files retrievable without credentials, with no available revoke path. No fixed version is available as of this review.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-285",
        "CWE-639"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79917.json"
}
References

Affected packages

Git / github.com/1panel-dev/maxkb

Affected ranges

Type
GIT
Repo
https://github.com/1panel-dev/maxkb
Events
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "2.7.0"
        },
        {
            "last_affected":  "2.10.4-lts"
        },
        {
            "fixed":  "2.10.4-lts"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION"
    ]
}

Affected versions

v2.*
v2.10.0-lts
v2.10.2-lts
v2.7.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v2.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79917.json"