📦 Mindsdb

by Mindsdb

🔍 What is Mindsdb?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2024-45856

CRITICAL CVSS 9.0 Sep 12, 2024

A stored cross-site scripting (XSS) vulnerability in MindsDB allows attackers to inject malicious JavaScript into ML Engine, database, project, or dataset names. When users view these objects in the w...

CVE-2024-24759

CRITICAL CVSS 9.3 Sep 5, 2024

This CVE describes a server-side request forgery (SSRF) vulnerability in MindsDB that allows attackers to bypass SSRF protection using DNS rebinding techniques. Attackers can potentially access intern...

CVE-2023-50731

CRITICAL CVSS 9.1 Dec 22, 2023

This is a path injection vulnerability in MindsDB that allows attackers to write arbitrary files to the server filesystem and delete zip/tar.gz files. It affects all MindsDB instances prior to version...

CVE-2023-38699

CRITICAL CVSS 9.1 Aug 4, 2023

MindsDB versions before 23.7.4.0 had disabled SSL certificate verification in requests, allowing man-in-the-middle attacks to intercept and potentially modify data between MindsDB and external data so...

CVE-2025-68472

HIGH CVSS 8.1 Jan 12, 2026

CVE-2025-68472 is an unauthenticated path traversal vulnerability in MindsDB's file upload API that allows attackers to read arbitrary files from the server filesystem and move them into MindsDB's sto...

CVE-2024-45852

HIGH CVSS 8.8 Sep 12, 2024

CVE-2024-45852 is a deserialization vulnerability in MindsDB that allows remote code execution when malicious models are uploaded. Attackers can execute arbitrary code on the server by exploiting unsa...

CVE-2024-45854

HIGH CVSS 7.1 Sep 12, 2024

This vulnerability allows remote code execution on MindsDB servers through deserialization of untrusted data in uploaded models. Attackers can execute arbitrary code when a 'describe' query is run on ...

CVE-2024-45848

HIGH CVSS 8.8 Sep 12, 2024

This vulnerability allows remote code execution on MindsDB servers when the ChromaDB integration is installed. Attackers can execute arbitrary Python code by sending specially crafted INSERT queries t...

CVE-2024-45850

HIGH CVSS 8.8 Sep 12, 2024

This vulnerability allows remote code execution on MindsDB servers when the Microsoft SharePoint integration is installed. Attackers can craft malicious INSERT queries containing Python code that gets...

CVE-2024-45846

HIGH CVSS 8.8 Sep 12, 2024

This vulnerability allows remote code execution on MindsDB servers when the Weaviate integration is installed. Attackers can execute arbitrary Python code by crafting malicious SELECT WHERE clauses ag...

CVE-2023-30620

HIGH CVSS 7.5 Apr 21, 2023

CVE-2023-30620 is a path traversal vulnerability in mindsdb's tarball extraction that allows attackers to write files to arbitrary locations on the server. This affects all users running mindsdb versi...