Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

MindsDB — Vulnerabilities & Security Advisories 23

All 23 CVE vulnerabilities found in MindsDB, with AI-generated Chinese analysis, references, and POCs.

This page provides a comprehensive overview of cybersecurity vulnerabilities associated with the Mindsdb product, categorized by weakness type and specific security tags. It aggregates known issues, tracking the historical record of security advisories and bug reports to ensure transparency regarding the software’s security posture. The content collected here encompasses a wide variety of vulnerability types, including but not limited to injection flaws, cross-site scripting, and improper access control mechanisms. The data covers security incidents from the product's initial public release through the most recent months, offering a long-term perspective on how the development team has addressed security concerns over time. This range allows users to identify patterns in vulnerability discovery and remediation efforts. Visitors can use this resource to track the vendor’s response to critical security advisories and monitor the timeline of fixes for specific issue classes. By examining the aggregated data, users can gain a deeper understanding of the prevalent weakness classes affecting the system and assess the overall maturity of its security practices. Additionally, individuals can look up the specific vulnerability history of Mindsdb to evaluate risks for their own deployments or to understand how similar products handle comparable security challenges. This centralized view supports informed decision-making for security professionals, developers, and stakeholders who rely on accurate and up-to-date information about the product’s security landscape without needing to navigate multiple disparate sources or perform manual CVE lookups.

Vendor: mindsdb

CVE IDTitleCVSSSeverityPublished
CVE-2026-7712 MindsDB Pickle pickle.loads deserialization CWE-502 6.3 Medium2026-05-03
CVE-2026-7711 MindsDB Engine proc_wrapper.py exec unrestricted upload CWE-434 7.3 High2026-05-03
CVE-2026-27483 MindsDB has Path Traversal in /api/files Leading to Remote Code Execution CWE-22 8.8 High2026-02-24
CVE-2026-2531 MindsDB File Upload security.py clear_filename server-side request forgery CWE-918 6.3 Medium2026-02-16
CVE-2025-68472 MindsDB has improper sanitation of filepath that leads to information disclosure and DOS CWE-22 8.1 High2026-01-12
CVE-2024-45856 MindsDB 安全漏洞 CWE-79 9.0 Critical2024-09-12
CVE-2024-45855 MindsDB 安全漏洞 CWE-502 7.1 High2024-09-12
CVE-2024-45854 MindsDB 安全漏洞 CWE-502 7.1 High2024-09-12
CVE-2024-45853 MindsDB 安全漏洞 CWE-502 7.1 High2024-09-12
CVE-2024-45852 MindsDB 安全漏洞 CWE-502 8.8 High2024-09-12
CVE-2024-45851 MindsDB 安全漏洞 CWE-95 8.8 High2024-09-12
CVE-2024-45850 MindsDB 安全漏洞 CWE-95 8.8 High2024-09-12
CVE-2024-45849 MindsDB 安全漏洞 CWE-95 8.8 High2024-09-12
CVE-2024-45848 MindsDB 安全漏洞 CWE-95 8.8 High2024-09-12
CVE-2024-45847 MindsDB 安全漏洞 CWE-95 8.8 High2024-09-12
CVE-2024-45846 MindsDB 安全漏洞 CWE-95 8.8 High2024-09-12
CVE-2024-24759 MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding CWE-918 9.3 Critical2024-09-05
CVE-2023-50731 MindsDB has arbitrary file write in file.py CWE-918 9.1 Critical2023-12-22
CVE-2023-49796 MindsDB Arbitrary File Write vulnerability CWE-20 5.3 Medium2023-12-11
CVE-2023-49795 MindsDB Server-Side Request Forgery vulnerability CWE-918 6.5 Medium2023-12-11
CVE-2023-38699 MindsDB 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue CWE-311 9.1 Critical2023-08-04
CVE-2023-30620 Arbitrary File Write when Extracting a Remotely retrieved Tarball in mindsdb/mindsdb CWE-22 7.5 High2023-04-21
CVE-2022-23522 Arbitrary File Write when Extracting Tarballs retrieved from a remote location using in mindsdb CWE-22 8.5 High2023-03-30

All 23 known CVE vulnerabilities affecting MindsDB with full Chinese analysis, references, and POCs where available.