MindsDBGHSA-93c5-rj2p-w52x
Cross-site Scripting (XSS) in mindsdb/mindsdb
Medium5.8CVE-2024-3575 · Published Apr 16, 2024 · updated Jun 6, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mindsdb PyPI | <= 23.6.3.1 | No fix yet |
Details and references
When a user uploads a csv file that contains an javascript payload a Cross-site Scripting (XSS) is triggered when the file is viewed. This is true for both cloud version and OSS version.
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:L/I:N/A:N
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-79
- Also known as
- CVE-2024-3575, PYSEC-2024-288
More MindsDB advisories
All MindsDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Dec 152023 | GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182 CVE-2023-50731High9.1fixed in 23.11.4.1 | High9.1 | 23.11.4.1 |
| Dec 122023 | Improper Input Validation in mindsdb CVE-2023-49796Medium5.3fixed in 23.11.4.1 | Medium5.3 | 23.11.4.1 |
| Dec 122023 | Server-Side Request Forgery in mindsdb CVE-2023-49795Medium6.5fixed in 23.11.4.1 | Medium6.5 | 23.11.4.1 |
| Sep 52024 | MindsDB Vulnerable to Bypass of SSRF Protection with DNS Rebinding CVE-2024-24759High9.3fixed in 23.12.4.2 | High9.3 | 23.12.4.2 |
| Sep 122024 | MindsDB Eval Injection vulnerability CVE-2024-45848High8.8fixed in 24.7.4.1 | High8.8 | 24.7.4.1 |
| Sep 122024 | MindsDB Eval Injection vulnerability CVE-2024-45849High8.8fixed in 24.7.4.1 | High8.8 | 24.7.4.1 |