MaxKB's CVSS 10.0 CVE: Patch Fixed Shell Quoting, Not the Approval Gate
On Sep 21 MaxKB, an open-source agent platform on Python, Django and LangChain with ~22,900 GitHub stars, received a CVSS 10.0: the agent's shell tool is not excluded and is missing from interrupt_on, so a prompt injected via ingested knowledge-base content can become command execution. The v2.10.5-lts fix (commit 594f50f2) replaced the string wrapper with shlex parsing and re-quoting, but the approval-gate line in tools.py at that tag still does not name execute. Three sibling CVEs (5.4 and 5.0) remain marked with no patched version.
- CVE-2026-77521 scored CVSS 10.0: agent shell tool lacks an approval gate
- v2.10.5-lts fix (594f50f2) addressed shlex quoting, not the gate
- At tag v2.10.5-lts, interrupt_on has no execute key
- Three sibling CVEs (5.4 and 5.0) marked with no fixed version
Read next
Security