CVE-2026-27483Disclosure(mindsdb / mindsdb)

LOWCVSS 8.8 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch mindsdb mindsdb systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The vulnerability exists in the "Upload File" module, which corresponds to the API endpoint /api/files. Since the multipart file upload does not perform security checks on the uploaded file path, an attacker can perform path traversal by using `../` sequences in the filename field. The file write operation occurs before calling clear_filename and save_file, meaning there is no filtering of filenames or file types, allowing arbitrary content to be written to any path on the server. Version 25.9.1.1 patches the issue.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

AVAILABLE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • mindsdb

Threat summary

  • Patch or workaround signal is available
  • 8 mentions across 4 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 3 signals
  • Technical details provided in 8 signals
  • Disclosure: 5 classified signals
  • General: 1 classified signal
  • Peaked 3d ago at 3 mentions (2026-02-24); latest day: 1
  • 8 total mentions across 4 days

Affected systems

Vendors
Products
mindsdb

Deep dive

Activity timeline8 mentions / 4d
01223Mentions · 2026-02-24: 3Mentions · 2026-02-25: 3Mentions · 2026-03-01: 1Mentions · 2026-03-16: 1Patch / Workaround · 2026-02-24: 1Patch / Workaround · 2026-02-25: 2Technical Details · 2026-02-24: 3Technical Details · 2026-02-25: 3Technical Details · 2026-03-01: 1Technical Details · 2026-03-16: 102-2402-2503-0103-16
Signal classification3 categories
Disclosure
562.5%
Patch
225.0%
General
112.5%
Referenced assets8 URLs
Classification over time
DateTotalLabels
2026-02-243
Disclosure2Patch1
2026-02-253
Disclosure2Patch1
2026-03-011
General1
2026-03-161
Disclosure1
Full discourse8 posts
  • pdnuclei-bot@pdnuclei_bot
    Disclosure

    🚨 CVE-2026-27483 - high 🚨 MindsDB - Remote Code Execution > MindsDB < 25.9.1.1 contains a remote code execution caused by path traversal in the /... 👾 https://cloud.projectdiscovery.io/library/CVE-2026-27483 @pdnuclei #NucleiTemplates #cve

    Post summary

    The tweet announces CVE-2026-27483, declaring that MindsDB < 25.9.1.1 suffers a remote code execution vulnerability due to path traversal, with no exploit tool, patch, or active exploitation data provided.

    00044221
    901 followersView on X
  • The Hacker Wire@TheHackerWire
    Disclosure

    🟠 CVE-2026-27483 - High MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an... https://www.thehackerwire.com/vulnerability/CVE-2026-27483/ https://t.co/m2SkreEG8J

    Post summary

    The post announces a path traversal vulnerability (CVE-2026-27483) in MindsDB's /api/files interface, noting the affected version and providing a link for further details.

    0001058
    115 followersView on X
  • CVEFind.com@CveFindCom
    Patch

    [CVE-2026-27483: HIGH] Platform MindsDB had a path traversal vulnerability in version prior to 25.9.1.1, which could lead to remote command execution. Upgrade to the latest version to patch the issue.#cve,CVE-2026-27483,#cybersecurity https://cvefind.com/CVE-2026-27483

    Post summary

    The post highlights a high‑severity path traversal flaw in MindsDB that could enable remote command execution and recommends upgrading to the latest version to mitigate the risk.

    0001056
    584 followersView on X
  • CVETodo@CveTodo
    Disclosure

    **CVE-2026-27483** is a path traversal vulnerability present in MindsDB versions prior to **25.9.1.1**. It affects the `/api/files` endpoint responsible for uploading files via the "Upload File" module. The flaw arises because the system does not validate or sanitize the filename provided during multipart file uploads, allowing an attacker to include directory traversal sequences (`../`) in the filename. This can lead to arbitrary file write operations on the server, enabling an attacker to overwrite critical files or place malicious files in sensitive locations. #Cybersecurity #CVE #HighSeverity #SecurityAlert #RemoteCodeExecution #DDoS https://cvetodo.com/cve/CVE-2026-27483

    Post summary

    A path traversal flaw in MindsDB versions before 25.9.1.1 allows attackers to write arbitrary files via the /api/files upload endpoint, potentially overwriting critical files.

    0001054
    20 followersView on X
  • CRAC Learning - Tech@cracbot
    General

    CVE-2026-27483 (CVSS:8.8, HIGH) is Analyzed. MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a p..https://nvd.nist.gov/vuln/detail/CVE-2026-27483 #cybersecurityawareness #cybersecurity #CVE #infosec #hacker #nvd #mitre

    Post summary

    The post references CVE-2026-27483 with a high CVSS score and links to the NVD entry, but provides no details on PoC, exploit, or patch.

    0000028
    173 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-27483 MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/… https://www.cve.org/CVERecord?id=CVE-2026-27483

    Post summary

    A path traversal vulnerability (CVE-2026-27483) exists in MindsDB before version 25.9.1.1, which is presumably fixed in that release.

    00000179
    56.6K followersView on X
  • PulsePatch.io@pulsepatchio
    Patch

    A path traversal flaw (CVE-2026-27483) in `MindsDB`'s `/api/files` endpoint can lead to remote code execution. Patching is recommended. #MindsDB #RCE #infosec https://www.pulsepatch.io/posts/cve-2026-27483-mindsdb-path-traversal-rce

    Post summary

    A path traversal vulnerability (CVE‑2026‑27483) in MindsDB’s /api/files endpoint can lead to remote code execution; patching is recommended.

    0000060
    1 followersView on X
  • cvereports@_cvereports
    Disclosure

    CVE-2026-27483: Lobotomy by File Upload: RCE in MindsDB via Path Traversal A critical path traversal vulnerability in MindsDB allows authenticated attackers to break out of the upload sandbox and overwrite arbitrary system files. By manipulating the '... https://cvereports.com/reports/CVE-2026-27483

    Post summary

    The report details a critical path traversal flaw in MindsDB that lets authenticated users overwrite system files, but it does not provide a PoC, exploit code, or patch information.

    0000047
    31 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appmindsdbmindsdb---

Explore more