{
  "schema_version": "1.6.0",
  "id": "ACVE-2026-0428",
  "aliases": [
    "CVE-2026-77521",
    "GHSA-f36j-f34j-h3rx"
  ],
  "published": "2026-09-02T00:00:00Z",
  "modified": "2026-09-25T00:00:00Z",
  "summary": "MaxKB <=2.10.3-lts, asked to answer a chat with tools attached, let the agent use its shell backend to execute commands on the host instead of keeping the work inside the intended sandbox.",
  "details": "## What\n\nThe MaxKB advisory says chats with a tool, MCP tool, skill or sub-application are routed through a deepagents shell backend that exposes an execute tool. On affected deployments, the agent can run host commands, including when the input arrives through untrusted chat or ingested content.\n\n## Detection\n\nThe advisory includes a research reproduction on MaxKB 2.10.3-lts.\n\n## Fix\n\nUpgrade to MaxKB 2.10.5-lts and do not expose shell execution to untrusted assistant input.",
  "affected": [
    {
      "package": {
        "ecosystem": "AgentHarness",
        "name": "maxkb"
      },
      "ranges": [
        {
          "type": "SEMVER",
          "events": [
            {
              "introduced": "0"
            },
            {
              "fixed": "2.10.5-lts"
            }
          ]
        }
      ]
    }
  ],
  "references": [
    {
      "type": "ADVISORY",
      "url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
    }
  ],
  "database_specific": {
    "severity": "CRITICAL",
    "acve": {
      "specVersion": 1,
      "status": "candidate",
      "kind": "code",
      "vulnClasses": [
        "command-injection",
        "over-privileged-combination",
        "exposed-surface"
      ],
      "cwe": [
        "CWE-78",
        "CWE-250",
        "CWE-749"
      ],
      "taxonomy": {
        "owasp_asi": [
          "ASI05",
          "ASI02"
        ],
        "atlas": [
          "AML.T0053",
          "AML.T0050"
        ]
      },
      "cveBoundary": "cve-aliased",
      "exploitation": {
        "status": "demonstrated",
        "checkedAt": "2026-09-24T00:00:00Z",
        "sources": [
          {
            "url": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx",
            "type": "research"
          }
        ],
        "kev": {
          "listed": false
        }
      },
      "fix": {
        "summary": "Upgrade MaxKB to 2.10.5-lts and remove untrusted access to shell-capable assistants.",
        "actions": [
          {
            "type": "upgrade",
            "target": "harness:maxkb",
            "to": "2.10.5-lts",
            "why": "First patched version in the advisory.",
            "owner": "operator"
          }
        ]
      },
      "exposure": {
        "harness": {
          "value": "MaxKB <=2.10.3-lts with an assistant that has a tool, MCP tool, skill or sub-application attached",
          "any": false,
          "status": "confirmed",
          "source": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
        },
        "model": {
          "value": "any",
          "any": true,
          "status": "unconfirmed"
        },
        "goal": {
          "value": "Any chat task handled by the tool-attached assistant",
          "stated": false,
          "status": "unconfirmed"
        },
        "tools": {
          "value": "The deepagents shell backend and its execute tool; MAXKB_SANDBOX may be unset or bypassed",
          "status": "confirmed",
          "source": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
        },
        "approval": {
          "value": "The execute tool is not included in the listed interrupt approvals",
          "mode": "none-required",
          "status": "confirmed",
          "source": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
        },
        "inputControl": "content-author",
        "agentAction": "The agent executes shell commands on the host or application container.",
        "harm": "arbitrary-command",
        "divergence": "none",
        "reach": {
          "value": "The host or application container and reachable internal services",
          "kinds": [
            "root",
            "network"
          ],
          "status": "confirmed",
          "source": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
        },
        "condition": {
          "value": "When untrusted chat or ingested content reaches a tool-attached assistant",
          "status": "confirmed",
          "source": "https://github.com/1Panel-dev/MaxKB/security/advisories/GHSA-f36j-f34j-h3rx"
        }
      },
      "claims": [
        {
          "kind": "identifier",
          "statement": "Identifier CVE-2026-77521",
          "value": "CVE-2026-77521",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-77521",
          "result": "match",
          "observed": "CVE.org: PUBLISHED",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:23Z"
        },
        {
          "kind": "identifier",
          "statement": "Identifier GHSA-f36j-f34j-h3rx",
          "value": "GHSA-f36j-f34j-h3rx",
          "status": "confirmed",
          "source": "https://api.github.com/repos/1Panel-dev/MaxKB/security-advisories/GHSA-f36j-f34j-h3rx",
          "result": "match",
          "observed": "GitHub repository security advisory: record found",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:23Z"
        },
        {
          "kind": "fixed-version",
          "statement": "Fixed in 2.10.5-lts",
          "value": "2.10.5-lts",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-77521",
          "result": "match",
          "observed": "CVE.org structured: lessThan 2.10.5-lts; CVE.org description: fixed 2.10.5-lts",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:23Z"
        },
        {
          "kind": "severity",
          "statement": "Severity CRITICAL; matches CNA",
          "status": "confirmed",
          "source": "https://cveawg.mitre.org/api/cve/CVE-2026-77521",
          "observed": "CNA: CRITICAL 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H); OSV: CRITICAL 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)",
          "result": "match",
          "method": "machine",
          "checkedAt": "2026-09-24T18:58:23Z"
        }
      ],
      "reproducibility": {
        "status": "partial",
        "axesComplete": true,
        "componentsObtainable": null,
        "triggerPublished": false,
        "observableStated": true,
        "demonstrated": "researcher-demonstrated",
        "missing": [
          "vulnerable components are not confirmed obtainable",
          "trigger not published"
        ]
      }
    }
  }
}
