Executive brief
MindsDB is an open-source machine learning platform that provides a web interface for managing ML engines, databases, projects, and datasets. A cross-site scripting (XSS) vulnerability allows attackers with authenticated access to inject arbitrary JavaScript code that executes whenever users enumerate these objects, potentially enabling session hijacking, data theft, or unauthorized actions performed on behalf of the victim.
Technical details
A stored cross-site scripting (XSS) vulnerability (CWE-79) exists in MindsDB's web UI that allows authenticated users to inject arbitrary JavaScript code into ML Engine, database, project, or dataset names or configurations. The injected payload executes in the browser context of any other user who enumerates these objects. Exploitation requires an authenticated attacker and user interaction (viewing affected objects), but the impact includes high confidentiality, integrity, and availability risks through session token theft, credential harvesting, or malware injection. The vulnerability affects all versions up to at least v24.9.2.1; patch status should be verified against official MindsDB release notes.
Affected products
- MindsDB MindsDB up to 24.9.2.1
Timeline
- 2024-09-12: disclosed
- 2024-09-12: other: Published as GHSA-32fj-r8qw-r8w8, CVE-2024-45856