CVE-2025-68472 is an unauthenticated path traversal vulnerability in MindsDB, affecting versions prior to 25.11.1. This flaw allows an attacker to read arbitrary files from the server's filesystem and move them into MindsDB's storage, potentially exposing sensitive data. With a CVSS score of 9.1 (CRITICAL), it is easily exploitable over the network without authentication or user interaction, leading to high confidentiality and availability impacts. Currently, there is no evidence of active exploitation, and no public exploit code (Metasploit, Nuclei, ExploitDB) is available, though it has received minimal community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 25.11.1CPE matchmatch criteria | cpe:2.3:a:mindsdb:mindsdb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.