VulnSea

mindsdb vulnerabilities

CVEs whose affected-version data names the mindsdb package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.

7 CVEsRSS

CVE-2026-86173High· 7.5PoC
2w ago

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list

MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can …

Midnightmindsdb · mindsdbEPSS 0.37%via NVD
CVE-2026-7711High· 7.3
4mo ago

MindsDB has an Improper Access Control Issue

MindsDB has an Improper Access Control Issue

Twilightmindsdb · mindsdbEPSS 0.28%via OSV
CVE-2026-27483High· 8.8PoC
7mo ago

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

MindsDB: Path Traversal in /api/files Leading to Remote Code Execution

Midnightmindsdb · mindsdbEPSS 11%via OSV
CVE-2024-45847High· 8.8
2y ago

MindsDB Eval Injection vulnerability

MindsDB Eval Injection vulnerability

Twilightmindsdb · mindsdbEPSS 0.85%via OSV
CVE-2024-45856Critical· 9.0
2y ago

MindsDB Cross-site Scripting vulnerability

MindsDB Cross-site Scripting vulnerability

Midnightmindsdb · mindsdbEPSS 0.51%via OSV
CVE-2023-49795Medium· 6.5
2y ago

Server-Side Request Forgery in mindsdb

Server-Side Request Forgery in mindsdb

Sunlitmindsdb · mindsdbEPSS 0.42%via OSV
CVE-2023-30620High· 7.5
3y ago

mindsdb arbitrary file write when extracting a remotely retrieved Tarball

mindsdb arbitrary file write when extracting a remotely retrieved Tarball

Twilightmindsdb · mindsdbEPSS 0.99%via OSV
mindsdb vulnerabilities (CVEs) · VulnSea