Metrics
Affected Vendors & Products
Tue, 14 Apr 2026 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 13 Apr 2026 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
1panel
1panel maxkb |
|
| Vendors & Products |
1panel
1panel maxkb |
Sun, 12 Apr 2026 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability was found in 1Panel-dev MaxKB up to 2.6.1. The affected element is the function execute of the file apps/application/flow/step_node/mcp_node/impl/base_mcp_node.py of the component Model Context Protocol Node. Performing a manipulation results in os command injection. The attack is possible to be carried out remotely. The exploit has been made public and could be used. You should upgrade the affected component. The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product. | |
| Title | 1Panel-dev MaxKB Model Context Protocol Node base_mcp_node.py execute os command injection | |
| First Time appeared |
Maxkb
Maxkb maxkb |
|
| Weaknesses | CWE-77 CWE-78 |
|
| CPEs | cpe:2.3:a:maxkb:maxkb:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Maxkb
Maxkb maxkb |
|
| References |
| |
| Metrics |
cvssV2_0
|
Status: PUBLISHED
Assigner: VulDB
Published:
Updated: 2026-04-14T14:00:16.365Z
Reserved: 2026-04-11T07:35:04.182Z
Link: CVE-2026-6108
Updated: 2026-04-14T14:00:12.824Z
Status : Awaiting Analysis
Published: 2026-04-12T01:16:16.807
Modified: 2026-04-13T15:01:43.663
Link: CVE-2026-6108
No data.
OpenCVE Enrichment
Updated: 2026-04-13T12:56:28Z