Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Mindsdb

First CVE: Mar 30, 2023Active for: 3 yearsTotal CVEs: 22
60.6
VTI Score
TOP TARGET

MindsDB is an open-source machine-learning infrastructure platform designed to integrate AI models with databases and applications, maintaining a concentrated but prominent footprint in the ML-ops and data-integration landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the inherent risks of dynamic code generation and data-processing intermediaries. The exposure concentrates in the core MindsDB platform and recurs through weakness classes centered on code injection, eval injection, path traversal, unsafe deserialization, and server-side request forgery—attack vectors endemic to systems that execute user-supplied logic or bridge untrusted data sources to privileged backend systems. Defenders should treat MindsDB deployments as high-value targets for code-execution attacks, particularly in environments where the platform bridges to sensitive databases or production infrastructure, and should prioritize patching releases that address injection and deserialization flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
22
Total CVEs
More Total CVEs than 96% of tracked vendors
7.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
7.8
Avg CVSS Score
Higher Avg CVSS Score than 76% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Mindsdb over time

Volume of CVEsAvg CVSS Base Score
First CVE
Mar 30, 2023
3 years ago
Most Recent CVE
Feb 24, 2026
150 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (22 CVEs).

22 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-27483HIGH
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interfac
Feb 24, 20268.857NOYES
CVE-2025-68472CRITICAL
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller
Jan 12, 20269.142NONO
CVE-2024-24759CRITICAL
MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on
Sep 5, 20249.142NOYES
CVE-2023-50731CRITICAL
MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` does not validate the user-contro
Dec 22, 20239.128NONO
CVE-2022-23522HIGH
MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archive()` from a remotely retrieved tarball. Which may lead to th
Mar 30, 20238.828NONO
CVE-2024-45846HIGH
An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specia
Sep 12, 20248.826NONO
CVE-2024-45852HIGH
Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when i
Sep 12, 20248.825NONO
CVE-2024-45851HIGH
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
Sep 12, 20248.825NONO
CVE-2024-45850HIGH
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
Sep 12, 20248.825NONO
CVE-2024-45849HIGH
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server.
Sep 12, 20248.825NONO
View all 22 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products22 CVEs
23%
64%
14%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local0 (0.0%)
Network22 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low19 (86.4%)
High3 (13.6%)
Unknown0 (0.0%)
User Interaction
None20 (90.9%)
Unknown0 (0.0%)
Required2 (9.1%)
Privileges Required
Low14 (63.6%)
High0 (0.0%)
None8 (36.4%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (22 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
2 CVEs
9.1% of CVEs· 96th percentile
ExploitDB
1 CVE
4.5% of CVEs· 75th percentile

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Mindsdb.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Mindsdb — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Mindsdb's Products

View all 4 CNAs →

Top CWEs