Monitor vulnerabilities like this one. Sign up free to get alerted when software you use is affected.
6.9

MaxKB AI Assistant: Malicious Code Can Run in Other Users' Browsers

CVE-2026-39423
Summary

MaxKB's chat interface in versions 2.7.1 and below can let attackers inject malicious code into other users' browsers, including admins. This can lead to stolen data or compromised accounts. Update to version 2.8.0 or later to fix the issue.

Original title
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting wi...
Original description
MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting with the AI chat interface to execute arbitrary JavaScript in the browsers of other users, including administrators, resulting in Stored Cross-Site Scripting (XSS). This issue has been fixed in version 2.8.0.
nvd CVSS4.0 6.9
Vulnerability type
CWE-79 Cross-site Scripting (XSS)
CWE-95
Published: 14 Apr 2026 · Updated: 15 Apr 2026 · First seen: 14 Apr 2026