CVEPublished 2026-04-140 articles on news5 live referencesNVD data

CVE-2026-39423

Vulnerability data via NVD (ingested)

CVSS v3.1
EPSS percentile
Description

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain an Eval Injection vulnerability in the Markdown rendering engine that allows any user capable of interacting with the AI chat interface to execute arbitrary JavaScript in the browsers of other users, including administrators, resulting in Stored Cross-Site Scripting (XSS). This issue has been fixed in version 2.8.0.

Timeline
Published 2026-04-14
Modified 2026-04-14

External references

Search for exposed instances

Shodan + Censys queries derived from NVD's CPE data. The vuln tag catches assets Shodan has explicitly linked to this CVE; the product / banner fingerprints find exposed instances even when the vuln tag was never applied (which is common).

More intel sources (5)

Known PoCs on GitHub

No public proof-of-concept repositories found for CVE-2026-39423 on GitHub.
We haven't classified any articles referencing CVE-2026-39423 yet. The external references above still apply.