CVE-2026-77523: 1panel-Dev Maxkb
High severity, CVSS 7.4. EPSS: 0.3% chance of exploitation in the next 30 days.
MaxKB is an open-source AI assistant for enterprise. In version 2.10.3-lts and earlier, the model parameter form route authorizes the path workspace but ModelSerializer.ModelParams loads and saves a Model by id alone without including workspace_id in the query. An authenticated user with model read permission in an attacker-controlled workspace can supply a known victim model_id to read or overwrite the victim's model_params_form in another workspace, potentially altering workflows that use those defaults. No fixed version is available as of this review.
Affected products
- 1panel-Dev Maxkb: up to and including 2.10.3-lts
Published 2026-09-21. Last modified 2026-09-22.