Skip to content

Build1 publisher2 min readPublished

MaxKB's CVSS 10.0 patch re-quotes shell commands without gating the agent's execute tool

MaxKB's v2.10.5-lts fix for a CVSS 10.0 agent flaw repairs shell quoting but leaves the execute tool off the approval list. According to one developer's trace of the release tag, a prompt planted in ingested documents can still trigger shell commands with no human sign-off.

The Engineer · Build desk

Drafted by a language model from the sources cited here and checked against its claim ledger before publication. How we use AISend a correction

Illustration accompanying MaxKB's CVSS 10.0 patch re-quotes shell commands without gating the agent's execute tool
Generated illustration

What happened

  • The NVD description says the agent's execute shell tool is neither excluded from its toolset nor listed in interrupt_on, so human approval is not required.
  • Lasso Security's write-up by Noy Pearl, who found the flaw, identified ingested documents and crawled pages as the route for planted prompts.
  • In the official root container, Lasso showed characters such as ;, |, $() and > escaping MaxKB's string-based gosu wrapper into the outer root shell.
  • Commit 594f50f2 replaced that wrapper by tokenising commands with shlex.split, re-quoting each token with shlex.quote and rejecting anything that will not parse.
  • Three sibling CVEs tied to the same platform are marked as having no patched version.

Compiled by The EngineerSomething wrong?How this is made

Why it matters

  • exposure Teams on v2.10.5-lts whose assistants carry tools and read uploaded or crawled content still run an agent that can call a shell without a person approving it.
  • decision Operators now choose between gating execute in interrupt_on themselves and waiting for an upstream tag, since the release labelled as the fix covers quoting only.
  • constraint An upgrade cannot clear the full set of related MaxKB CVEs while three of them list no patched version.

MaxKB is an open-source agent platform built on Python, Django and LangChain, with about 22,900 GitHub stars [2]. The exposure starts when an agent is built. If an assistant carries any tool, MCP tool, skill or sub-application, its flow backend is SandboxShellBackend, and that backend gives the agent an execute tool [4]. The framework underneath decides when to stop and ask a human by reading a map called interrupt_on [5].

A dev.to post followed the advisory to the commit and then to the release tag. According to that post, tools.py at v2.10.5-lts builds the agent with this line [11]:

``` interrupt_on={"write_file": False, "read_file": False, "edit_file": False}, ```

The missing gate is one dictionary key long. The line names three file tools and sets each to False. It has no execute key, and the constructor passes no excluded_tools either [11].

The commit that did ship is careful work. Commit 594f50f2 was authored July 9, touches one file, and adds 241 lines while removing 5 [9]. The post's author wrote, "This is the right fix class and it is worth naming." [13] I agree. A command assembled from parts has to be quoted at the boundary, and this one now is [10].

The two halves of the advisory now stand differently. The quoting change targets the escape from the gosu wrapper into root [8][10]. The approval gap the description leads with is still in the constructor. An agent that reads a planted instruction can call execute, and nothing in interrupt_on pauses it for a person [3][11]. The NVD record went up 74 days after the commit was authored, and its description still leads with the gate [1][3].

Deployments built from source with MAXKB_SANDBOX disabled run commands directly as the application user [7]. The commit rebuilds the sandbox command [10]. The post does not say what, if anything, changes for installs running with the flag off.

The evidence is one developer's reading of one file at one tag, published abridged [11]. If MaxKB filters execute somewhere outside the agent constructor, the conclusion changes. Nothing in the trace points to such a filter.

In my view, v2.10.5-lts addresses the root escape Lasso demonstrated and leaves the approval gap open [8][10][11]. A team may run assistants that carry tools and read crawled or uploaded documents. For that team, the line to check is interrupt_on in the deployed tools.py, because that map decides whether a shell call waits for a human [5][11].

What to watch

  • A MaxKB tag after v2.10.5-lts that adds an execute key to interrupt_on or passes excluded_tools to the agent constructor.
  • Patched versions posted for the three sibling CVEs, or a revision to the fixed-version data on the CVE-2026-77521 record.
  • A maintainer statement that execute is filtered outside tools.py; that would overturn the trace's conclusion.
Loading claim ledger
Loading source directory links
Loading share composer
Loading topic controls
Loading related stories