Skip to content
MindsDBGHSA-9gq6-6936-885w

MindsDB Eval Injection vulnerability

High8.8CVE-2024-45848 · Published Sep 12, 2024 · updated Sep 16, 2024

GitHub advisory

Affected versions

PackageAffectedFixed in
mindsdb
PyPI
>= 23.12.4.0, < 24.7.4.124.7.4.1
Details and references

An arbitrary code execution vulnerability exists in versions 23.12.4.0 up to 24.7.4.1 of the MindsDB platform, when the ChromaDB integration is installed on the server. If a specially crafted ‘INSERT’ query containing Python code is run against a database created with the ChromaDB engine, the code will be passed to an eval function and executed on the server.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94, CWE-95
Also known as
CVE-2024-45848, PYSEC-2024-78

More MindsDB advisories

All MindsDB
DateAdvisory
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45849High8.8fixed in 24.7.4.1
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45847High8.8fixed in 24.7.4.1
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45850High8.8fixed in 24.7.4.1
Sep 122024MindsDB Eval Injection vulnerability
CVE-2024-45846High8.8fixed in 24.7.4.1
Sep 122024MindsDB Cross-site Scripting vulnerability
CVE-2024-45856Medium9.0no fix yet
Sep 122024MindsDB Deserialization of Untrusted Data vulnerability
CVE-2024-45854High7.1no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.