A significant vulnerability in MaxKB, identified as CVE-2026-77521, could enable attackers to execute arbitrary shell commands through AI assistants integrated with tools, MCP servers, skills, or sub-applications This article explores vulnerability maxkb. . The vulnerability carries a CVSS v3.1 score of 10.0, requiring no authentication or user interaction for network-based exploitation.
Researchers at Lasso Security discovered that an attacker can exploit an exposed agent execution path to run commands on the underlying host or, in containerized deployments, potentially execute commands as root. Critical MaxKB AI Agent Flaw MaxKB utilizes deepagents agents to route conversations whenever an assistant is connected to a tool, MCP server, skill, or sub-application. Although MaxKB outlines approval behavior for file-related operations such as write_file, read_file, and edit_file, it fails to incorporate human-in-the-loop controls for the execute capability.
Consequently, untrusted inputs submitted through a chat interface or malicious instructions embedded in documents processed via retrieval-augmented generation workflows can influence the underlying model to execute operating-system commands. This vulnerability is particularly concerning for public or embedded assistants that accept anonymous input, as well as multi-tenant deployments where one user’s content could impact an agent handling sensitive data or internal services. Successful exploitation could lead to unauthorized access to secrets, configuration files, probing of internal services, lateral movement, persistence, or affecting other tenants sharing the same environment.
Organizations should upgrade to MaxKB 2.10.5-lts immediately.











