CVE-2025-64703
BaseFortify
Publication date: 2025-11-13
Last updated on: 2025-12-04
Assigner: GitHub, Inc.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| maxkb | maxkb | to 2.3.1 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-200 | The product exposes sensitive information to an actor that is not explicitly authorized to have access to that information. |
| CWE-NVD-CWE-noinfo |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
In MaxKB versions prior to 2.3.1, a user can obtain sensitive information by executing Python code in the tool module, even though the process runs in a sandbox environment. This vulnerability allows unauthorized access to sensitive data.
How can this vulnerability impact me? :
This vulnerability can lead to unauthorized disclosure of sensitive information, potentially compromising confidentiality, integrity, and availability of data within the affected system.
What immediate steps should I take to mitigate this vulnerability?
Upgrade MaxKB to version 2.3.1 or later, as this version fixes the vulnerability allowing sensitive information disclosure via Python code in the tool module sandbox.