vciy

CVEs we hold for Mindsdb

Records whose assigning authority named Mindsdb as the affected vendor. Newest identifiers first, capped at 200.

CVE-2026-86173MindsDB through 26.1.0 Unauthenticated SSRF via Web Crawlermindsdb
CVE-2026-7712MindsDB Pickle pickle.loads deserializationn/a MindsDB
CVE-2026-7711MindsDB Engine proc_wrapper.py exec unrestricted uploadn/a MindsDB
CVE-2026-73678MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()MindsDB Minds Platform
CVE-2026-27483MindsDB has Path Traversal in /api/files Leading to Remote Code Executionmindsdb
CVE-2026-2531MindsDB File Upload security.py clear_filename server-side request forgeryn/a MindsDB
CVE-2025-68472MindsDB has improper sanitation of filepath that leads to information disclosure and DOSmindsdb
CVE-2024-45856no title heldmindsdb
CVE-2024-45855no title heldmindsdb
CVE-2024-45854no title heldmindsdb
CVE-2024-45853no title heldmindsdb
CVE-2024-45852no title heldmindsdb
CVE-2024-45851no title heldmindsdb
CVE-2024-45850no title heldmindsdb
CVE-2024-45849no title heldmindsdb
CVE-2024-45848no title heldmindsdb
CVE-2024-45847no title heldmindsdb
CVE-2024-45846no title heldmindsdb
CVE-2024-3575Cross-site Scripting (XSS) - Stored in mindsdb/mindsdbmindsdb/mindsdb
CVE-2024-24759MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebindingmindsdb
CVE-2023-50731MindsDB has arbitrary file write in file.pymindsdb
CVE-2023-49796MindsDB Arbitrary File Write vulnerabilitymindsdb
CVE-2023-49795MindsDB Server-Side Request Forgery vulnerabilitymindsdb
CVE-2023-38699MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issuemindsdb
CVE-2023-30620Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdbmindsdb
CVE-2022-23522Arbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdbmindsdb

26 records, read from the index as it stood on 20 Sep 2026. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.