Vendor
Unauthenticated SSRF Vulnerability in MindsDB Crawler
1 TTP 1 CVEMindsDB versions 26.1.0 and earlier are vulnerable to unauthenticated server-side request forgery (SSRF) in the web crawler handler, enabling unauthorized access to internal resources and cloud metadata.
Unauthenticated Remote Code Execution in MindsDB Minds Platform
1 rule 1 TTP 1 CVEMindsDB Minds Platform versions 26.1.0 and earlier are vulnerable to unauthenticated remote code execution via insecure handling of LLM prompts and unsandboxed scratchpad execution.
MindsDB Unrestricted File Upload Vulnerability (CVE-2026-7711)
2 rules 1 TTP 1 CVECVE-2026-7711 allows for remote, unrestricted file uploads in MindsDB up to version 26.01 due to insufficient validation in the `exec` function of `proc_wrapper.py`, potentially leading to code execution or data exfiltration.
MindsDB Path Traversal Vulnerability Leading to Remote Code Execution
3 rules 2 TTPs 1 CVEA path traversal vulnerability in MindsDB versions prior to 25.9.1.1 allows an attacker to achieve remote code execution by uploading a malicious payload and triggering its execution.