MindsDBGHSA-9f6m-65v9-x9g2
MindsDB has an Improper Access Control Issue
Medium7.3CVE-2026-7711 · Published May 4, 2026 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mindsdb PyPI | <= 26.0.1 | No fix yet |
Details and references
A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wrapper.py of the component Engine Handler. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-284
- Also known as
- CVE-2026-7711, PYSEC-2026-2648
More MindsDB advisories
All MindsDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 24 | MindsDB: Path Traversal in /api/files Leading to Remote Code Execution CVE-2026-27483High8.8fixed in 25.9.1.1 | High8.8 | 25.9.1.1 |
| Feb 16 | MindsDB affected by a SSRF vulnerability CVE-2026-2531Low6.3no fix yet | Low6.3 | No fix yet |
| Jan 12 | MindsDB has improper sanitation of filepath that leads to information disclosure and DOS CVE-2025-68472High8.1fixed in 25.11.1 | High8.1 | 25.11.1 |
| Sep 122024 | MindsDB Cross-site Scripting vulnerability CVE-2024-45856Medium9.0no fix yet | Medium9.0 | No fix yet |
| Sep 122024 | MindsDB Deserialization of Untrusted Data vulnerability CVE-2024-45854High7.1no fix yet | High7.1 | No fix yet |
| Sep 122024 | MindsDB Deserialization of Untrusted Data vulnerability CVE-2024-45852High8.8no fix yet | High8.8 | No fix yet |