VYPR
Moderate severityNVD Advisory· Published Apr 16, 2024· Updated Aug 1, 2024

Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb

CVE-2024-3575

Description

Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Stored XSS in MindsDB allows attackers to inject malicious scripts that execute in victims' browsers.

Vulnerability

Overview

MindsDB, an open-source platform for building AI applications, is affected by a stored cross-site scripting (XSS) vulnerability [1]. The flaw, tracked as CVE-2024-3575, allows an attacker to inject arbitrary JavaScript code that is stored by the application and later executed when other users access the affected component.

Exploitation

An attacker with the ability to submit input to MindsDB (e.g., via query names, model names, or other user-controllable fields) can inject malicious scripts. No authentication is required if the input is accepted from unauthenticated users; however, the exact attack surface depends on the deployment configuration. When an administrator or other user views the injected data, the script executes in their browser context.

Impact

Successful exploitation can lead to session hijacking, unauthorized actions on behalf of the victim, data theft (including credentials), or defacement of the application interface. Since the XSS is stored, the payload remains persistent and can affect all users who access the compromised data.

Mitigation

The vulnerability was reported via the huntr bug bounty platform [3]. Users should upgrade to a patched version of MindsDB as recommended by the maintainers [2]. No workaround is currently available.

AI Insight generated on May 20, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected packages

Versions sourced from the GitHub Security Advisory.

PackageAffected versionsPatched versions
mindsdbPyPI
<= 23.6.3.1

Affected products

2
  • ghsa-coords
    Range: <= 23.6.3.1
  • mindsdb/mindsdb/mindsdbv5
    Range: unspecified

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

3

News mentions

0

No linked articles in our index yet.