Vulnerabilities
CVE-2025-66446 - MaxKB has a Python sandbox LD_PRELOAD bypass
CVE ID : CVE-2025-66446 Published : Dec. 11, 2025, 10:15 p.m. | 1 hour, 25 minutes ago Description : MaxKB is an open-source AI assistant for enterprise. Versions 2.3.1 and below have improper file permissions which allow attackers to overwrite the built-in dynamic linker and other critical files, potentially resulting in privilege escalation. This issue is fixed in version 2.4.0. Severity: 8.8 | HIGH Visit the link for more details, such as CVSS details, affected products, timeline, and more...
CVE Details
Impact:
privilege escalation
Source: Telegram CVE Monitor