Security: mindsdb/mindshub
Security Advisories
View known security vulnerabilities and report new vulnerabilities privately to maintainers.
-
Unauthenticated Remote Code Execution via Agent Scratchpad 'exec()' in 'POST /api/v1/responses/'GHSA-jcxw-h8ph-pxpv published
Jul 17, 2026 by ZoranPandovskiCritical -
Path Traversal in /api/files Leading to Remote Code ExecutionGHSA-4894-xqv6-vrfq published
Feb 22, 2026 by hamishfaggHigh -
Improper sanitation of filepath that leads to information disclosure and DOS in MindsDBGHSA-qqhf-pm3j-96g7 published
Jan 11, 2026 by ZoranPandovskiHigh -
Bypass SSRF Protection with DNS RebindingGHSA-4jcv-vp96-94xr published
Sep 5, 2024 by ZoranPandovskiCritical -
GitHub Security Lab (GHSL) Vulnerability Report: GHSL-2023-184GHSA-crhp-7c74-cg4c published
Dec 11, 2023 by ZoranPandovskiModerate -
GitHub Security Lab (GHSL) Vulnerability Report: Arbitary write GHSL-2023-182GHSA-j8w6-2r9h-cxhj published
Dec 14, 2023 by ZoranPandovskiModerate -
GitHub Security Lab (GHSL) Vulnerability Report GHSL-2023-182GHSA-34mr-6q8x-g9r6 published
Dec 11, 2023 by ZoranPandovskiModerate -
Fix 'Call to requests with verify=False disabling SSL certificate checks, security issue.' issue in mindsdb\integrations\handlers\dremio_handler\dremio_handler.pyGHSA-8hx6-qv6f-xgcw published
Aug 1, 2023 by ZoranPandovskiCritical -
Arbitrary File Write when Extracting a Remotely retrieved Tarball using `Tarfile.extractall()` in mindsdb/mindsdbGHSA-2g5w-29q9-w6hx published
Mar 30, 2023 by ZoranPandovskiHigh -
Arbitrary File Write when Extracting Tarballs retrieved from a remote location using `shutil.unpack_archive()`GHSA-7x45-phmr-9wqp published
Mar 30, 2023 by ZoranPandovskiHigh