Medium severity4.3NVD Advisory· Published Sep 21, 2026· Updated Sep 21, 2026
CVE-2026-77522
CVE-2026-77522
Description
MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the knowledge web-document import and synchronization crawler passes an authenticated workspace user's URL to Fork.fork, which calls requests.get with verify=False and without restricting schemes, loopback, link-local, private, or reserved addresses. The response body is converted into imported document content, allowing a low-privileged user to read cloud metadata or internal HTTP services through the MaxKB server. No fixed version is available as of this review.
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.