mindsdb has 7 CVEs on record between 2023 and 2026. 1 was published in the last 90 days. The median CVSS is 7.5 (high), with 1 rated critical. None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.5
- Publish → KEV
- —
- Last 90 days
- 1 prev 1
Weakness classes
Products
- mindsdb 7
Worst active — by depth score
CVE-2026-27483High· 8.8MindsDB: Path Traversal in /api/files Leading to Remote Code Execution63CVE-2026-86173High· 7.5MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list53CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability50CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability49CVE-2023-30620High· 7.5mindsdb arbitrary file write when extracting a remotely retrieved Tarball41
mindsdb vulnerabilities
CVEs affecting mindsdb, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2026-86173High· 7.5PoCMindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list
MindsDB through 26.1.0 contains a server-side request forgery vulnerability in the web crawler handler that allows unauthenticated attackers to fetch arbitrary URLs by supplying caller-controlled URLs to CrawlerTable.list. Attackers can …
CVE-2026-7711High· 7.3MindsDB has an Improper Access Control Issue
MindsDB has an Improper Access Control Issue
CVE-2026-27483High· 8.8PoCMindsDB: Path Traversal in /api/files Leading to Remote Code Execution
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2024-45847High· 8.8MindsDB Eval Injection vulnerability
MindsDB Eval Injection vulnerability
CVE-2024-45856Critical· 9.0MindsDB Cross-site Scripting vulnerability
MindsDB Cross-site Scripting vulnerability
CVE-2023-49795Medium· 6.5Server-Side Request Forgery in mindsdb
Server-Side Request Forgery in mindsdb
CVE-2023-30620High· 7.5mindsdb arbitrary file write when extracting a remotely retrieved Tarball
mindsdb arbitrary file write when extracting a remotely retrieved Tarball