Skip to content
MindsDBGHSA-32fj-r8qw-r8w8

MindsDB Cross-site Scripting vulnerability

Medium9.0CVE-2024-45856 · Published Sep 12, 2024 · updated Jul 7, 2026

A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
<= 24.9.2.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-79
Also known as
CVE-2024-45856, PYSEC-2026-1628

More MindsDB advisories

All MindsDB
Advisory
MindsDB Deserialization of Untrusted Data vulnerability
High7.1Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High8.8Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High7.1Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High7.1Sep 12, 2024
MindsDB Eval Injection vulnerability
High8.8Sep 12, 2024
MindsDB Eval Injection vulnerability
High8.8Sep 12, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.