Ghostwire

CVE-2026-79919: MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under...

MEDIUM CVSS 0.0 EPSS 0.28%

Published: September 21, 2026 | Last Modified: September 21, 2026

Description

MaxKB is an open-source AI assistant for enterprise. Prior to version 2.10.6-lts, function-library code running under the LD_PRELOAD sandbox can invoke ctypes.CDLL from an importlib.abc.MetaPathFinder callback so the dlopen call-stack heuristic sees a Python import frame, then use unhooked dlsym with RTLD_NEXT to resolve glibc's real syscall and bypass the sandbox syscall blacklist. An authenticated workspace member can consequently read or write files, execute processes, or access networks as the sandbox user. This issue is fixed in version 2.10.6-lts.

Ghostwire Analysis — What This Means Practically

Exploitation Probability (EPSS): Low — 0.28% (21th percentile)

Low exploitation probability based on current threat landscape data. Standard patching timeline is appropriate.

This analysis is generated by Ghostwire from NVD, CISA KEV, EPSS, and open-source intelligence data. Verify findings through primary sources before acting.

Security Coverage (1 articles)

References