MindsDB is an open-source machine-learning infrastructure platform designed to integrate AI models with databases and applications, maintaining a concentrated but prominent footprint in the ML-ops and data-integration landscape. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity and a moderate tendency toward public exploit availability, reflecting the inherent risks of dynamic code generation and data-processing intermediaries. The exposure concentrates in the core MindsDB platform and recurs through weakness classes centered on code injection, eval injection, path traversal, unsafe deserialization, and server-side request forgery—attack vectors endemic to systems that execute user-supplied logic or bridge untrusted data sources to privileged backend systems. Defenders should treat MindsDB deployments as high-value targets for code-execution attacks, particularly in environments where the platform bridges to sensitive databases or production infrastructure, and should prioritize patching releases that address injection and deserialization flaws. Live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Mindsdb over time
Signals from CVEs in this vendor scope (22 CVEs).
22 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2026-27483HIGH MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interfac | Feb 24, 2026 | 8.8 | 57 | NO | YES |
CVE-2025-68472CRITICAL MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller | Jan 12, 2026 | 9.1 | 42 | NO | NO |
CVE-2024-24759CRITICAL MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 23.12.4.2, a threat actor can bypass the server-side request forgery protection on | Sep 5, 2024 | 9.1 | 42 | NO | YES |
CVE-2023-50731CRITICAL MindsDB is a SQL Server for artificial intelligence. Prior to version 23.11.4.1, the `put` method in `mindsdb/mindsdb/api/http/namespaces/file.py` does not validate the user-contro | Dec 22, 2023 | 9.1 | 28 | NO | NO |
CVE-2022-23522HIGH MindsDB is an open source machine learning platform. An unsafe extraction is being performed using `shutil.unpack_archive()` from a remotely retrieved tarball. Which may lead to th | Mar 30, 2023 | 8.8 | 28 | NO | NO |
CVE-2024-45846HIGH An arbitrary code execution vulnerability exists in versions 23.10.3.0 up to 24.7.4.1 of the MindsDB platform, when the Weaviate integration is installed on the server. If a specia | Sep 12, 2024 | 8.8 | 26 | NO | NO |
CVE-2024-45852HIGH Deserialization of untrusted data can occur in versions 23.3.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded model to run arbitrary code on the server when i | Sep 12, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-45851HIGH An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. | Sep 12, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-45850HIGH An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. | Sep 12, 2024 | 8.8 | 25 | NO | NO |
CVE-2024-45849HIGH An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. | Sep 12, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (22 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Mindsdb.
Media articles that mention a CVE ID that affects a product developed by Mindsdb — matched by CVE ID, not by vendor name.