Vulnerability  ·  2026-07-31

MaxKB Enterprise AI Assistant - SSRF via Unvalidated Download/Callback URLs in UpdateStoreTool

VulnerabilityMedium impactGlobalCVE-2026-64870
Enables an authenticated but otherwise low-privilege workspace user to pivot into internal network resources via the MaxKB server, potentially reaching cloud metadata endpoints or internal admin interfaces not normally exposed.
UpdateStoreTool.update_tool passes caller-supplied download_url and download_callback_url values to requests.get without trusted-host or redirect validation, allowing an authenticated workspace user to trigger SSRF against internal services.
MaxKB 2.0.0 through 2.10.4-lts
Upgrade per the GitHub commit fix; add trusted-host allowlisting and redirect validation to outbound requests in tool-management code.
GitHub commit - MaxKB SSRF fixNVD - CVE-2026-64870
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →