VYPR
Medium severityNVD Advisory· Published May 26, 2026· Updated Jul 24, 2026

CVE-2026-45412

CVE-2026-45412

Description

MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetched server-side without any URL validation or internal IP filtering. This vulnerability is fixed in 2.9.1.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

2
  • 1panel Dev/Maxkbinferred2 versions
    <2.9.1+ 1 more
    • (no CPE)range: <2.9.1
    • (no CPE)range: <2.9.1

Patches

Vulnerability mechanics

References

1

News mentions

0

No linked articles in our index yet.