Skip to content
MindsDBGHSA-9f6m-65v9-x9g2

MindsDB has an Improper Access Control Issue

Medium7.3CVE-2026-7711 · Published May 4, 2026 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
<= 26.0.1No fix yet
Details and references

A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wrapper.py of the component Engine Handler. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-284
Also known as
CVE-2026-7711, PYSEC-2026-2648

More MindsDB advisories

All MindsDB
DateAdvisory
Feb 24MindsDB: Path Traversal in /api/files Leading to Remote Code Execution
CVE-2026-27483High8.8fixed in 25.9.1.1
Feb 16MindsDB affected by a SSRF vulnerability
CVE-2026-2531Low6.3no fix yet
Jan 12MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
CVE-2025-68472High8.1fixed in 25.11.1
Sep 122024MindsDB Cross-site Scripting vulnerability
CVE-2024-45856Medium9.0no fix yet
Sep 122024MindsDB Deserialization of Untrusted Data vulnerability
CVE-2024-45854High7.1no fix yet
Sep 122024MindsDB Deserialization of Untrusted Data vulnerability
CVE-2024-45852High8.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.