/Vulnerability Library

MindsDB - Remote Code Execution

CVE-2026-27483
Verified

Description

MindsDB < 25.9.1.1 contains a remote code execution caused by path traversal in the /api/files upload file module, letting authenticated attackers write arbitrary files and execute commands, exploit requires authentication.

Severity

High

CVSS Score

8.8

Exploit Probability

9%

Affected Product

MindsDB

Published Date

March 6, 2026

Template Author

thewhiteh4t

CVE-2026-27483.yaml
8.8Score

CVSS Metrics

CVSS Vector:
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CVE ID:
cve-2026-27483
CWE ID:
cwe-22

References

https://github.com/mindsdb/mindsdb/security/advisories/GHSA-4894-xqv6-vrfqhttps://github.com/mindsdb/mindsdb/commit/87a44bdb2b97f963e18f10a068e1a1e2690505efhttps://github.com/mindsdb/mindsdb/releases/tag/v25.9.1.1https://nvd.nist.gov/vuln/detail/CVE-2026-27483

Remediation Steps

Upgrade to version 25.9.1.1 or later.