Critical severity9.0NVD Advisory· Published Sep 12, 2024· Updated Jun 17, 2026
CVE-2024-45856
CVE-2024-45856
Description
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
mindsdbPyPI | <= 24.9.2.1 | — |
Affected products
3Patches
Vulnerability mechanics
References
4- hiddenlayer.com/sai-security-advisory/2024-09-mindsdb/nvdExploitThird Party Advisory
- github.com/advisories/GHSA-32fj-r8qw-r8w8ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-45856ghsaADVISORY
- hiddenlayer.com/sai-security-advisory/2024-09-mindsdbghsaWEB
News mentions
0No linked articles in our index yet.