Skip to content
MindsDBGHSA-6xw9-2p64-7622

MindsDB affected by a SSRF vulnerability

Low6.3CVE-2026-2531 · Published Feb 16, 2026 · updated Jun 6, 2026

A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
<= 25.14.1No fix yet
Details and references

More MindsDB advisories

All MindsDB
Advisory
MindsDB has an Improper Access Control Issue
Medium7.3May 4
MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
High8.8Feb 24
MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
High8.1Jan 12
MindsDB Cross-site Scripting vulnerability
Medium9.0Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High7.1Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High8.8Sep 12, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.