CVE-2026-39426: MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom <...

Added to the CISA Known Exploited Vulnerabilities catalog on 14 Apr 2026. Vendor: AI/ML. Product: LLM. CVSS score: 5.4.

MaxKB is an open-source AI assistant for enterprise. Versions 2.7.1 and below contain a Stored Cross-Site Scripting (XSS) vulnerability where the frontend's MdRenderer.vue component parses custom <iframe_render> tags from LLM responses or Application Prologue configurations, bypassing standard Ma...

Required action: Review and patch if applicable to your AI infrastructure.