CVE-2026-79918

Source
https://cve.org/CVERecord?id=CVE-2026-79918
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79918.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-79918
Aliases
  • GHSA-9mh9-v949-fwqh
Published
2026-09-21T20:47:13Z
Modified
2026-09-23T08:12:38Z
Severity
  • 6.3 (Medium) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
Summary
MaxKB: Sandbox escape via unhooked fexecve
Details

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, the ToolExecutor LD_PRELOAD sandbox hooks execve, execvpe, and execveat to prevent subprocess creation but does not hook fexecve. An authenticated attacker able to execute tool code can call fexecve to start a process outside the sandbox's intended subprocess policy. This issue is fixed in version 2.10.6-lts.

Database specific
{
    "cna_assigner":  "GitHub_M",
    "cwe_ids":  [
        "CWE-693"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/79xxx/CVE-2026-79918.json"
}
References

Affected packages

Git / github.com/1panel-dev/maxkb

Affected ranges

Type
GIT
Repo
https://github.com/1panel-dev/maxkb
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "2.10.6-lts"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "REFERENCES"
    ]
}

Affected versions

v0.*
v0.9.0
v0.9.1
v1.*
v1.0.0
v1.0.1
v1.1.0
v1.1.1
v1.1.2
v1.1.3
v1.10.0-lts
v1.10.1-lts
v1.10.2-lts
v1.10.3-lts
v1.10.4-lts
v1.2.0
v1.2.1
v1.3.0
v1.4.0
v1.5.0
v1.6.0
v1.6.1
v1.7.0
v1.9.0
v2.*
v2.0.0
v2.0.1
v2.0.2
v2.1.0
v2.10.0-lts
v2.10.1-lts
v2.10.3-lts
v2.10.5-lts
v2.2.0
v2.3.0
v2.4.0
v2.5.0
v2.6.0
v2.6.1
v2.7.0
v2.8.0
v2.8.1
v2.9.0
v2.9.1
v2.9.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-79918.json"
vanir_signatures
[
    {
        "deprecated":  false,
        "digest":  {
            "line_hashes":  [
                "75077052850177193177317574178903112073",
                "62190396274156982111050170053442363881",
                "83163469106024455835596739385331578573",
                "320814248081691810098015520753740733475",
                "339404758880186494566788410455630541648",
                "46941268089219842115917306375112318350",
                "63411014263650257390757000760049639375",
                "309384069646534216607295468353953108823"
            ],
            "threshold":  0.9
        },
        "id":  "CVE-2026-79918-e0b5ce7f",
        "signature_type":  "Line",
        "signature_version":  "v1",
        "source":  "https://github.com/1panel-dev/maxkb/commit/6fa7947a85030b87977c4026f33af11ca10dd1e6",
        "target":  {
            "file":  "installer/sandbox.c"
        }
    }
]
vanir_signatures_modified
"2026-09-23T08:12:38Z"