ACVE-2026-0428
MaxKB <=2.10.3-lts, asked to answer a chat with tools attached, let the agent use its shell backend to execute commands on the host instead of keeping the work inside the intended sandbox.
Exposure
Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)
Claims
Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.
| Claim | Status | Source | Checked |
|---|---|---|---|
| Identifier CVE-2026-77521 | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Identifier GHSA-f36j-f34j-h3rx | Confirmed | api.github.com | 2026-09-24 |
| Fixed in 2.10.5-lts | Confirmed | cveawg.mitre.org | 2026-09-24 |
| Severity CRITICAL; matches CNA | Confirmed | cveawg.mitre.org | 2026-09-24 |
In the wild
demonstrated · research
Description
What
The MaxKB advisory says chats with a tool, MCP tool, skill or sub-application are routed through a deepagents shell backend that exposes an execute tool. On affected deployments, the agent can run host commands, including when the input arrives through untrusted chat or ingested content.
Detection
The advisory includes a research reproduction on MaxKB 2.10.3-lts.
Fix
Upgrade to MaxKB 2.10.5-lts and do not expose shell execution to untrusted assistant input.
Fix
Upgrade MaxKB to 2.10.5-lts and remove untrusted access to shell-capable assistants.
- Upgrade
harness:maxkbto2.10.5-lts. First patched version in the advisory. Owner: operator