TROYANOSYVIRUS
Back to CVEs

CVE-2025-32383

MEDIUM
4.3

Description

MaxKB (Max Knowledge Base) is an open source knowledge base question-answering system based on a large language model and retrieval-augmented generation (RAG). A reverse shell vulnerability exists in the module of function library. The vulnerability allow privileged‌ users to create a reverse shell. This vulnerability is fixed in v1.10.4-lts.

CVE Details

CVSS v3.1 Score4.3
SeverityMEDIUM
CVSS VectorCVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:U/C:L/I:L/A:L
Attack VectorNETWORK
ComplexityLOW
Privileges RequiredHIGH
User InteractionREQUIRED
Published4/10/2025
Last Modified8/1/2025
Sourcenvd
Honeypot Sightings0

Affected Products

maxkb:maxkb

Weaknesses (CWE)

CWE-94

IOC Correlations

No correlations recorded

This product uses data from the NVD API but is not endorsed or certified by the NVD.