Mindsdb
by Mindsdb
Source repositories
CVEs (25)
| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-7712 | Med | 0.41 | 6.3 | 0.00 | May 4, 2026 | A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may… | ||
| CVE-2024-3575 | Med | 0.40 | 6.1 | 0.00 | Apr 16, 2024 | Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb | ||
| CVE-2023-49795 | Med | 0.35 | 6.5 | 0.00 | Dec 11, 2023 | MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which… | ||
| CVE-2026-2531 | Med | 0.34 | 6.3 | 0.00 | Feb 16, 2026 | A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed… | ||
| CVE-2023-49796 | Med | 0.27 | 5.3 | 0.00 | Dec 11, 2023 | MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file write vulnerability in `file.py` Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue. |
- risk 0.41cvss 6.3epss 0.00
A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may…
- risk 0.40cvss 6.1epss 0.00
Cross-site Scripting (XSS) - Stored in mindsdb/mindsdb
- risk 0.35cvss 6.5epss 0.00
MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which…
- risk 0.34cvss 6.3epss 0.00
A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed…
- risk 0.27cvss 5.3epss 0.00
MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a limited file write vulnerability in `file.py` Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue.
Page 2 of 2