What is CVE-2026-64870?
CVE-2026-64870 is a Server-Side Request Forgery (SSRF) vulnerability in the MaxKB open-source AI assistant, affecting versions 2.0.0 through 2.10.4-lts. An authenticated user can exploit the improper validation of `download_url` and `download_callback_url` parameters in the `UpdateStoreTool.update_tool` function to make unauthorized requests to internal network resources. Immediate upgrade to the latest patched version is recommended.
Azərbaycanca: CVE-2026-64870, MaxKB açıq mənbəli AI köməkçisinin 2.0.0-dən 2.10.4-lts versiyalarına qədər olan versiyalarında autentifikasiya olunmuş istifadəçiyə `download_url` parametri vasitəsilə SSRF hücumu etməyə imkan verən zəiflikdir. Təsdiqlənmiş istifadəçi tərəfindən göndərilən URL-lər düzgün yoxlanılmadığı üçün daxili şəbəkə resurslarına icazəsiz giriş əldə edilə bilər. Təhlükəsizlik üçün dərhal ən son versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-918
FAQ2
Which versions of MaxKB are affected by CVE-2026-64870?
CVE-2026-64870 affects MaxKB versions 2.0.0 through 2.10.4-lts.
Is authentication required to exploit CVE-2026-64870?
Yes, an attacker must be an authenticated user to exploit CVE-2026-64870.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.