CVE Feed

    Dashboard / CVE / CVE-2026-39422

    CVE-2026-39422

    MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability through the application name or icon fields when creating an application. When a victim visits the public chat interface (/ui/chat/{access_token}), the ChatHeadersMiddleware retrieves the application data and directly inserts the unescaped application name and icon into the HTML response via string replacement. This allows an attacker to execute arbitrary JavaScript in the victim's browser context. This issue has been fixed in version 2.8.0.

    Published:Apr 14, 2026
    Last Modified:Apr 20, 2026
    EPS:Apr 14, 2026
    EPSS Score:0.00049
    CVSS Score:5.4

    Affected Products

    Vendor
    1panel
    Product
    Maxkb
    Vendor
    Maxkb
    Product
    Maxkb

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High