CVE-2026-2531Disclosure(mindsdb / mindsdb)

LOWCVSS 7.3 · HIGH

Signal is active with 2 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A security vulnerability has been detected in MindsDB up to 25.14.1. This vulnerability affects the function clear_filename of the file mindsdb/utilities/security.py of the component File Upload. Such manipulation leads to server-side request forgery. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The name of the patch is 74d6f0fd4b630218519a700fbee1c05c7fd4b1ed. It is best practice to apply a patch to resolve this issue.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-918

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

NONE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mindsdb

Threat summary

  • 2 mentions across 1 observed day

What's happening

  • Technical details provided in 1 signal
  • Disclosure: 2 classified signals
  • 2 total mentions across 1 day

Affected systems

Vendors
Products
mindsdb

Deep dive

Activity timeline2 mentions / 1d
01122Mentions · 2026-02-16: 2Technical Details · 2026-02-16: 102-16
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-2531 Server-Side Request Forgery in MindsDB File Upload Functionality via clear_filename https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-2531

    Post summary

    A Server‑Side Request Forgery vulnerability (CVE-2026-2531) was disclosed for MindsDB's file upload function, but no PoC, exploit, or patch information was provided.

    0001044
    4.0K followersView on X
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-2531 📊 Severity: 6.3 🚨 Risk Level: Medium 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-2531 #CVE-2026-2531 #CVE #Medium #CyberSecurity #InfoSec https://t.co/cAs41zMK89

    Post summary

    A new CVE (CVE-2026-2531) with a medium severity rating has been announced, but the tweet does not supply technical details, exploits, or mitigation steps.

    0000034
    56 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmindsdbmindsdb---

Explore more