MindsDBGHSA-6xw9-2p64-7622
MindsDB affected by a SSRF vulnerability
Low6.3CVE-2026-2531 · Published Feb 16, 2026 · updated Jun 6, 2026
A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mindsdb PyPI | <= 25.14.1 | No fix yet |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-918
- Also known as
- CVE-2026-2531, PYSEC-2026-91
- nvd.nist.gov/vuln/detail/CVE-2026-2531
- github.com/mindsdb/mindsdb/issues/12163
- github.com/mindsdb/mindsdb/pull/12213
- github.com/themavik/mindsdb/commit/74d6f0fd4b630218519a700fbee1c05c7fd4b1ed
- github.com/mindsdb/mindsdb
- github.com/pypa/advisory-database/tree/main/vulns/mindsdb/PYSEC-2026-91.yaml
- vuldb.com/?ctiid.346119
- vuldb.com/?id.346119
- vuldb.com/?submit.748219
More MindsDB advisories
All MindsDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 4 | MindsDB has an Improper Access Control Issue | Medium7.3 | No fix yet |
| Feb 24 | MindsDB: Path Traversal in /api/files Leading to Remote Code Execution | High8.8 | 25.9.1.1 |
| Jan 12 | MindsDB has improper sanitation of filepath that leads to information disclosure and DOS | High8.1 | 25.11.1 |
| Sep 122024 | MindsDB Cross-site Scripting vulnerability | Medium9.0 | No fix yet |
| Sep 122024 | MindsDB Deserialization of Untrusted Data vulnerability | High7.1 | No fix yet |
| Sep 122024 | MindsDB Deserialization of Untrusted Data vulnerability | High8.8 | No fix yet |