CVE-2024-45847High· 8.8▾ TwilightMindsDB Eval Injection vulnerability
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 48.4 · likelihood 0.2 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.9%
An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is run against a database created with the specified integration engine, the code will be passed to an eval function and executed on the server.
mindsdb >= 23.11.4.2, < 24.7.4.1Upgrade to a patched release:
mindsdb 24.7.4.1Connected by shared product, vendor, weakness, or advisory.
CVE-2023-49795Medium· 6.5Server-Side Request Forgery in mindsdb
CVE-2023-30620High· 7.5mindsdb arbitrary file write when extracting a remotely retrieved Tarball
CVE-2026-7711High· 7.3MindsDB has an Improper Access Control Issue
CVE-2026-27483High· 8.8MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability
CVE-2026-86173High· 7.5MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list