Executive brief
MindsDB, an open-source platform for building AI models from data, is vulnerable to a security flaw where malicious code can be hidden inside uploaded CSV files. If a user views one of these files, the hidden code can execute in their browser, potentially allowing an attacker to steal session information or perform actions on the user's behalf. This affects both the cloud-hosted and self-hosted versions of the software.
Technical details
A stored Cross-Site Scripting (XSS) vulnerability exists in MindsDB due to improper neutralization of input during the processing of CSV file uploads. An attacker can upload a CSV file containing a malicious JavaScript payload; when this file is subsequently viewed within the MindsDB interface (cloud or OSS), the payload executes in the context of the victim's browser. The vulnerability is tracked as CWE-79 and affects versions up to and including 23.6.3.1. While the CVSS vector indicates no user interaction, XSS typically requires a victim to view the malicious content. No official patch version was specified in the advisory.
Affected products
- MindsDB mindsdb <= 23.6.3.1
Timeline
- 2024-04-16: disclosed: NVD publication date
- 2024-04-16: advisory: GitHub Advisory published