Mindsdb
23 CVEs tracked. None of them is in CISA KEV.
This hub aggregates every CVE we track for Mindsdb, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.
Mindsdb CVEs per month
| Month | CVEs |
|---|---|
| 2024-10 | 0 |
| 2024-11 | 0 |
| 2024-12 | 0 |
| 2025-01 | 0 |
| 2025-02 | 0 |
| 2025-03 | 0 |
| 2025-04 | 0 |
| 2025-05 | 0 |
| 2025-06 | 0 |
| 2025-07 | 0 |
| 2025-08 | 0 |
| 2025-09 | 0 |
| 2025-10 | 0 |
| 2025-11 | 0 |
| 2025-12 | 0 |
| 2026-01 | 1 |
| 2026-02 | 2 |
| 2026-03 | 0 |
| 2026-04 | 0 |
| 2026-05 | 0 |
| 2026-06 | 0 |
| 2026-07 | 0 |
| 2026-08 | 0 |
| 2026-09 | 1 |
Severity
How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.
- Critical4
- High15
- Medium4
Latest CVEs
The 15 most recently published vulnerabilities affecting Mindsdb.
- CVE-2026-86173MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawler7.5
- CVE-2026-27483MindsDB has Path Traversal in /api/files Leading to Remote Code Execution8.8
- CVE-2026-2531MindsDB File Upload security.py clear_filename server-side request forgery6.3
- CVE-2025-68472MindsDB has improper sanitation of filepath that leads to information disclosure and DOS8.1
- CVE-2024-45854MindsDB Deserialization of Untrusted Data vulnerability7.1
- CVE-2024-45847MindsDB Eval Injection vulnerability8.8
- CVE-2024-45856A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project,...9.0
- CVE-2024-45855Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when usi...7.1
- CVE-2024-45853Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when use...7.1
- CVE-2024-45852Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.8.8
- CVE-2024-45851An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
- CVE-2024-45850An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
- CVE-2024-45849An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
- CVE-2024-45848An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘IN...8.8
- CVE-2024-45846An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SE...8.8
Product grouping is registry-driven, with AI assist and human review. How it works