CVE-2025-66419 - MaxKB vulnerable to privilege escalation through sandbox bypass

CVE-2025-66419 - MaxKB vulnerable to privilege escalation through sandbox bypass

CVE ID : CVE-2025-66419 Published : Dec. 11, 2025, 10:15 p.m. | 1 hour, 25 minutes ago Description : MaxKB is an open-source AI assistant for enterprise. In versions 2.3.1 and below, the tool module allows an attacker to escape the sandbox environment and escalate privileges under certain concurrent conditions. This issue is fixed in version 2.4.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...

CVE Details

Severity
HIGH
Published
Dec. 11, 2025

Source: Telegram CVE Monitor