CVE-2026-6106 | 1Panel-dev MaxKB up to 2.2.1 Public Chat Interface static_headers_middleware.py StaticHeadersMiddleware Name cross site scripting (EUVD-2026-21686)
A vulnerability was found in 1Panel-dev MaxKB up to 2.2.1. It has been declared as problematic. This vulnerability affects the function StaticHeadersMiddleware of the file apps/common/middleware/static_headers_middleware.py of the component Public Chat Interface. The manipulation of the argument Name results in cross site scripting.
This vulnerability is cataloged as CVE-2026-6106. The attack may be launched remotely. Furthermore, there is an exploit available.
It is recommended to upgrade the affected component.
The vendor was contacted early, responded in a very professional manner and quickly released a fixed version of the affected product.