CVE-2025-32383

Severity CVSS v4.0:
Pending analysis
Type:
CWE-94 Code Injection
Publication date:
10/04/2025
Last modified:
01/08/2025

Description

MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability allow privileged‌ users to create a reverse shell. This vulnerability is fixed in v1.10.4-lts.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:maxkb:maxkb:*:*:*:*:lts:*:*:* 1.10.4 (excluding)