VYPR

Mindsdb

by Mindsdb

pypi: mindsdb

Source repositories

CVEs (24)

  • CVE-2026-73678CriAug 14, 2026
    risk 0.65cvss 10.0epss

    MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which…

  • CVE-2024-45856CriSep 12, 2024
    risk 0.59cvss 9.0epss 0.00

    A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.

  • CVE-2023-50731CriDec 22, 2023
    risk 0.59cvss 9.1epss 0.01

    MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` does not validate the user-controlled name value, which is used in a temporary file name, which is afterwards opened for writing on…

  • CVE-2024-45852HigSep 12, 2024
    risk 0.57cvss 8.8epss 0.01

    Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.

  • CVE-2022-23522HigMar 30, 2023
    risk 0.55cvss 8.5epss 0.01

    MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archive()` from a remotely retrieved tarball. Which may lead to the writing of the extracted files to an unintended location. This vulnerability is sometimes called…

  • CVE-2026-27483HigFeb 24, 2026
    risk 0.54cvss 8.8epss 0.11

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The…

  • CVE-2024-24759CriSep 5, 2024
    risk 0.54cvss 9.3epss 0.05

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on the whole website with DNS Rebinding. The vulnerability can also lead to denial of service.…

  • CVE-2023-38699CriAug 4, 2023
    risk 0.52cvss 9.1epss 0.00

    MindsDB's AI Virtual Database allows developers to connect any AI/ML model to any datasource. Prior to version 23.7.4.0, a call to requests with `verify=False` disables SSL certificate checks. This rule enforces always verifying SSL certificates for methods in the Requests…

  • CVE-2024-45851HigSep 12, 2024
    risk 0.50cvss 8.8epss 0.01

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list item…

  • CVE-2024-45850HigSep 12, 2024
    risk 0.50cvss 8.8epss 0.01

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for site…

  • CVE-2024-45849HigSep 12, 2024
    risk 0.50cvss 8.8epss 0.01

    An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘INSERT’ query can be used for list…

  • CVE-2024-45848HigSep 12, 2024
    risk 0.50cvss 8.8epss 0.01

    An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is run against a database created with the…

  • CVE-2024-45847HigSep 12, 2024
    risk 0.50cvss 8.8epss 0.01

    An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is run against a database created with the…

  • CVE-2024-45846HigSep 12, 2024
    risk 0.50cvss 8.8epss 0.02

    An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SELECT WHERE’ clause containing Python code is run against a database created with…

  • CVE-2025-68472HigJan 12, 2026
    risk 0.47cvss 8.1epss 0.20

    MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing…

  • CVE-2024-45855HigSep 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.

  • CVE-2024-45854HigSep 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.

  • CVE-2024-45853HigSep 12, 2024
    risk 0.46cvss 7.1epss 0.00

    Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when used for a prediction.

  • CVE-2023-30620HigApr 21, 2023
    risk 0.42cvss 7.5epss 0.01

    mindsdb is a Machine Learning platform to help developers build AI solutions. In affected versions an unsafe extraction is being performed using `tarfile.extractall()` from a remotely retrieved tarball. Which may lead to the writing of the extracted files to an unintended…

  • CVE-2026-7712MedMay 4, 2026
    risk 0.41cvss 6.3epss 0.00

    A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may…

Page 1 of 2