A vulnerability categorized as problematic has been discovered in 1Panel-dev MaxKB up to 2.7.x. This affects an unknown function of the component AI Chat Interface. The manipulation results in cross site scripting. This vulnerability was named CVE-2026-39423. The attack may be performed from remote. It is advisable to upgrade the affected component.
| Vendor | Product | Versions |
|---|---|---|
| 1panel-dev | maxkb | < 2.8.0 |
Updated description with new details, changed severity to HIGH, and noted that no exploit is available.
Initial creation