High severity7.5NVD Advisory· Published Sep 5, 2026
CVE-2026-86173
CVE-2026-86173
Description
MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can bypass the allowlist control by exploiting the default empty configuration and access internal services and cloud metadata endpoints without authentication.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1Patches
Vulnerability mechanics
References
4- github.com/mindsdb/mindshub/blob/v26.1.0/mindsdb/integrations/handlers/web_handler/web_handler.pynvd
- github.com/mindsdb/mindshub/blob/v26.1.0/mindsdb/utilities/config.pynvd
- github.com/mindsdb/mindshub/issues/12480nvd
- www.vulncheck.com/advisories/mindsdb-through-26.1.0-unauthenticated-ssrf-via-web-crawlernvd
News mentions
0No linked articles in our index yet.