Junglewise Threat Intelligence

CVE-2026-2531: MindsDB SSRF via URL validation bypass in File Upload

CVE-2026-2531 · Severity: medium · CVSS 6.3 · Published 2026-02-16

Technologies: mindsdb (PyPI). Vendors: PyPI.

Executive brief

MindsDB, an open-source platform for building AI applications, is vulnerable to a security flaw in its file upload and URL validation components. An attacker can bypass security filters to force the server to make unauthorized requests to internal or external systems. This could allow an attacker to access sensitive internal data, scan private networks, or disrupt internal services.

Technical details

A Server-Side Request Forgery (SSRF) vulnerability exists in MindsDB up to version 25.14.1 within the `_split_url` function of `mindsdb/utilities/security.py`. The root cause is the use of `urlparse().netloc` for origin validation, which includes the 'userinfo' component (e.g., user:pass@host). An attacker can craft a URL containing userinfo (e.g., `http://attacker@127.0.0.1`) to bypass blocklists that only check for the IP address or hostname. This allows a remote authenticated attacker to perform unauthorized requests to internal network services. A patch has been developed to replace `netloc` with a combination of `hostname` and `port` to properly strip userinfo during validation.

Affected products

  • MindsDB MindsDB <= 25.14.1

Timeline

  • 2026-02-10: patched: Pull request with fix submitted to GitHub repository
  • 2026-02-16: disclosed: Vulnerability disclosed and CVE-2026-2531 assigned
  • 2026-02-16: advisory: GitHub Advisory GHSA-6xw9-2p64-7622 published

References

Related threats