Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Thu, 04 Dec 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Maxkb
Maxkb maxkb |
|
| CPEs | cpe:2.3:a:maxkb:maxkb:*:*:*:*:-:*:*:* | |
| Vendors & Products |
Maxkb
Maxkb maxkb |
Fri, 14 Nov 2025 09:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel maxkb |
|
| Vendors & Products |
1panel
1panel maxkb |
Thu, 13 Nov 2025 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 13 Nov 2025 16:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | MaxKB is an open-source AI assistant for enterprise. In versions prior to 2.3.1, a user can access internal network services such as databases through Python code in the tool module, although the process runs in a sandbox. Version 2.3.1 fixes the issue. | |
| Title | MaxKB has SSRF in sandbox | |
| Weaknesses | CWE-918 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: GitHub_M
Published:
Updated: 2025-11-13T16:17:00.321Z
Reserved: 2025-11-05T21:15:39.399Z
Link: CVE-2025-64511
Updated: 2025-11-13T16:16:47.531Z
Status : Analyzed
Published: 2025-11-13T16:15:56.217
Modified: 2025-12-04T15:13:37.387
Link: CVE-2025-64511
No data.
OpenCVE Enrichment
Updated: 2025-11-14T09:27:58Z