ACVEAgent configuration vulnerability registry

ACVE-2026-0428

MaxKB <=2.10.3-lts, asked to answer a chat with tools attached, let the agent use its shell backend to execute commands on the host instead of keeping the work inside the intended sandbox.

Exposure

Reproducibility: partial (vulnerable components are not confirmed obtainable; trigger not published)

Claims

Confirmed means the statement matches the cited primary source. Nothing on this page has been reproduced.

ClaimStatusSourceChecked
Identifier CVE-2026-77521Confirmedcveawg.mitre.org2026-09-24
Identifier GHSA-f36j-f34j-h3rxConfirmedapi.github.com2026-09-24
Fixed in 2.10.5-ltsConfirmedcveawg.mitre.org2026-09-24
Severity CRITICAL; matches CNAConfirmedcveawg.mitre.org2026-09-24

In the wild

demonstrated · research

Description

What

The MaxKB advisory says chats with a tool, MCP tool, skill or sub-application are routed through a deepagents shell backend that exposes an execute tool. On affected deployments, the agent can run host commands, including when the input arrives through untrusted chat or ingested content.

Detection

The advisory includes a research reproduction on MaxKB 2.10.3-lts.

Fix

Upgrade to MaxKB 2.10.5-lts and do not expose shell execution to untrusted assistant input.

Fix

Upgrade MaxKB to 2.10.5-lts and remove untrusted access to shell-capable assistants.

  • Upgrade harness:maxkb to 2.10.5-lts. First patched version in the advisory. Owner: operator

References

ADVISORY

Report a problemJSON