MaxKB changelog: what's new each month
Every stable MaxKB release summarised by month: the highlights, new features, improvements, fixes and anything you need to act on. 3 months covered; the current month updates daily.
September 2026
1 release: 2.10.6-lts
September brought critical security fixes addressing multiple vulnerabilities across chat, document handling, user authentication, and sandbox isolation. This LTS release focuses on preventing content injection, unauthorized access, and system resource abuse.
Highlights
- Fixed sandbox bypass vulnerabilities in the function library that could allow arbitrary code execution.
- Patched cross-tenant content injection and data disclosure vulnerabilities affecting document migration and batch operations.
- Secured chat file uploads and application profile endpoints to prevent spoofing and sensitive configuration leakage.
- Added rate limiting to password reset verification to prevent account takeover attacks.
- Fixed memory exhaustion vulnerability in image decompression that could crash the service.
Fixed
- Chat file uploads can no longer spoof APPLICATION attribution or be read anonymously.
- Document and paragraph migration now validates destination tenant permissions to prevent cross-tenant content injection.
- XLSX image decompression now enforces pixel count limits to prevent memory exhaustion attacks.
- Batch association operations now require proper ownership validation.
- Anonymous application profile endpoint no longer exposes sensitive configuration data.
- Password reset verification endpoint now includes attempt rate limiting.
August 2026
2 releases: 2.10.5-lts → 1.10.15-lts
August brought critical security patches addressing privilege escalation vulnerabilities and API access control issues. The release also fixed several knowledge base and conversation handling problems.
Highlights
- Fixed multiple privilege escalation vulnerabilities that allowed unauthorized access to other users' data and workspace information.
- Resolved security flaw where chat-sharing links could expose other users' conversations without permission.
- Fixed knowledge base image loading failures in conversations and PDF paragraph formatting issues.
- Corrected display of the preview option in web knowledge base document import.
- Fixed text truncation when copying long conversation content from chats.
Fixed
- Missing owner checks on chat-sharing endpoints that could leak other users' conversation content.
- Privilege escalation allowing users to fetch information from other workspaces via API.
- Privilege escalation where any user's API key could delete arbitrary files.
- Users obtaining other users' sensitive information like email addresses through the API.
- Knowledge base images failing to load in conversations.
- PDF uploads showing garbled paragraph content when titles matched body text.
July 2026
2 releases: 2.10.3-lts → 2.10.4-lts
July brought significant security fixes alongside improvements to knowledge base uploads, agent configuration, and user interface polish. A critical vulnerability patch was released mid-month addressing multiple authorization and access control issues.
Highlights
- Knowledge base file uploads now show visual progress and support one-click re-upload for failed files.
- Major security update fixed multiple privilege escalation and unauthorized access vulnerabilities.
- Agent conversations with WeCom integration now support voice input capability.
- Batch configuration added for managing agent conversation log cleanup strategies.
- Fixed critical issue preventing variable assignment in advanced agent debugging.
New
- Visual progress display for knowledge base file uploads.
- One-click re-upload functionality for failed file uploads.
- Batch configuration for agent conversation log cleanup strategies.
- Voice input capability for WeCom robot integration.
- Homepage view permission configuration for regular users and workspace administrators.
Improved
- Agent overview page copywriting and visual style now align with homepage design.
- Authorization verification mechanism added for agent and workflow tool scheduling.
- Host validation added when UpdateStoreTool fetches external app store URLs.
Fixed
- System file permission flaw allowing anonymous access to resources.
- IDOR vulnerability in admin chat logs enabling cross-application chat record access.
- Horizontal privilege escalation issue allowing unauthorized document and segment access across knowledge bases.
- Expired agent API keys being usable at the /chat/api/mcp endpoint.
- Privilege escalation in MCP tool authorization logic.
- Multiple agents sharing same chatsessionid causing 500 errors in WeCom integration.
Summaries are written automatically from the official release notes (full changelog ↗); check the original notes before relying on a detail. MaxKB: pricing, features and alternatives · All changelogs
