CVE Tools

Mindsdb

23 CVEs tracked. None of them is in CISA KEV.

This hub aggregates every CVE we track for Mindsdb, a product in the oss libraries space. Use it to gauge the current risk picture and drill into individual advisories.

Mindsdb CVEs per month

Oct 2024 to Sep 2026. Point at a month, or focus the strip and use the arrow keys.
Mindsdb CVEs per month
MonthCVEs
2024-100
2024-110
2024-120
2025-010
2025-020
2025-030
2025-040
2025-050
2025-060
2025-070
2025-080
2025-090
2025-100
2025-110
2025-120
2026-011
2026-022
2026-030
2026-040
2026-050
2026-060
2026-070
2026-080
2026-091

Severity

How the 23 CVEs score on CVSS. Severity is not exploitation: KEV is counted above.

  • Critical417%
  • High1565%
  • Medium417%

Latest CVEs

The 15 most recently published vulnerabilities affecting Mindsdb.

  1. CVE-2026-86173MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawler7.5
  2. CVE-2026-27483MindsDB has Path Traversal in /api/files Leading to Remote Code Execution8.8
  3. CVE-2026-2531MindsDB File Upload security.py clear_filename server-side request forgery6.3
  4. CVE-2025-68472MindsDB has improper sanitation of filepath that leads to information disclosure and DOS8.1
  5. CVE-2024-45854MindsDB Deserialization of Untrusted Data vulnerability7.1
  6. CVE-2024-45847MindsDB Eval Injection vulnerability8.8
  7. CVE-2024-45856A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project,...9.0
  8. CVE-2024-45855Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when usi...7.1
  9. CVE-2024-45853Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when use...7.1
  10. CVE-2024-45852Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when interacted with.8.8
  11. CVE-2024-45851An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
  12. CVE-2024-45850An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
  13. CVE-2024-45849An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases cr...8.8
  14. CVE-2024-45848An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘IN...8.8
  15. CVE-2024-45846An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specially crafted ‘SE...8.8

Product grouping is registry-driven, with AI assist and human review. How it works

We use analytics cookies to see which pages and articles actually help people. Decline and none of them run — the site works the same. What we store