MindsDB has 8 CVEs on record between 2023 and 2026. 2 were published in the last 90 days. The median CVSS is 8.2 (high), with 2 rated critical. None have a confirmed exploitation report. Most affected products: mindsdb (7), Minds Platform (1).
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 8.2
- Publish → KEV
- —
- Last 90 days
- 2 prev 1
Worst active — by depth score
CVE-2026-73678Critical· 10.0MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()67CVE-2026-27483High· 8.8MindsDB: Path Traversal in /api/files Leading to Remote Code Execution63CVE-2026-86173High· 7.5MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list53CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability50CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability49
MindsDB vulnerabilities
CVEs affecting MindsDB, newest first. Open any entry for full detail, references, and exploit status.
8 CVEsRSS
CVE-2026-86173High· 7.5PoCMindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list
MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can …
CVE-2026-73678Critical· 10.0PoCMindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POS…
CVE-2026-7711High· 7.3MindsDB has an Improper Access Control Issue
MindsDB has an Improper Access Control Issue
CVE-2026-27483High· 8.8PoCMindsDB: Path Traversal in /api/files Leading to Remote Code Execution
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability
MindsDB Eval Injection vulnerability
CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability
MindsDB Cross-site Scripting vulnerability
CVE-2023-49795Medium· 6.5Server-Side Request Forgery in mindsdb
Server-Side Request Forgery in mindsdb
CVE-2023-30620High· 7.5mindsdb arbitrary file write when extracting a remotely retrieved Tarball
mindsdb arbitrary file write when extracting a remotely retrieved Tarball