CVE Feed

    Dashboard / CVE / CVE-2024-56137

    CVE-2024-56137

    MaxKB, which stands for Max Knowledge Base, is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). Prior to version 1.9.0, a remote command execution vulnerability exists in the module of function library. The vulnerability allow privileged‌ users to execute OS command in custom scripts. The vulnerability has been fixed in v1.9.0.

    Published:Jan 2, 2025
    Last Modified:Aug 1, 2025
    EPS:Jan 2, 2025
    EPSS Score:0.01032
    CVSS Score:6.8

    Affected Products

    Vendor
    Maxkb
    Product
    Maxkb

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High