Skip to content
MindsDBGHSA-7vhh-gfjc-x8rm

MindsDB Deserialization of Untrusted Data vulnerability

High7.1CVE-2024-45854 · Published Sep 12, 2024 · updated Sep 17, 2024

Deserialization of untrusted data can occur in versions 23.10.3.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when a ‘describe’ query is run on it.

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
>= 23.10.3.0, <= 24.9.2.1No fix yet
Details and references

More MindsDB advisories

All MindsDB
Advisory
MindsDB Cross-site Scripting vulnerability
Medium9.0Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High8.8Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High7.1Sep 12, 2024
MindsDB Deserialization of Untrusted Data vulnerability
High7.1Sep 12, 2024
MindsDB Eval Injection vulnerability
High8.8Sep 12, 2024
MindsDB Eval Injection vulnerability
High8.8Sep 12, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.