---
id: CVE-2024-45856
aliases:
  - GHSA-32fj-r8qw-r8w8
  - PYSEC-2026-1628
title: MindsDB Cross-site Scripting vulnerability
summary: MindsDB Cross-site Scripting vulnerability
severity: critical
cvss: 9
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H'
vendor: mindsdb
product: mindsdb
ecosystem: pip
affected:
  - mindsdb <= 24.9.2.1
published: '2024-09-12'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-32fj-r8qw-r8w8'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-45856'
  - url: 'https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb'
tags:
  - osv
  - pip
epss: 0.00506
epssPercentile: 0.40587
ingestedAt: '2026-07-08T18:25:44.643Z'
---

## Overview

A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.

## Affected packages

- `mindsdb <= 24.9.2.1`

## Remediation

Refer to the advisory for the patched release.
