Critical MaxKB AI Agent Flaw Lets Prompt Injection Execute Commands as Root
A critical vulnerability in MaxKB, tracked as CVE-2026-77521, could allow attackers to use prompt injection to trigger arbitrary shell commands through AI assistants configured with tools, MCP integrations, skills, or sub-applications.
The flaw affects MaxKB versions up to and including 2. 10. 3-lts and has been fixed in version 2. 10. 5-lts. The issue carries a CVSS v3. 1 score of 10. 0, with network-based exploitation requiring no authentication or user interaction.
Researchers at Lasso Security reported that an attacker can exploit an exposed agent execution path to run commands on the underlying host or, in containerized deployments, potentially execute commands as root.
Critical MaxKB AI Agent Flaw
MaxKB routes conversations through a deepagents agent whenever an assistant has a connected tool, MCP server , skill, or sub-application.