Junglewise Threat Intelligence

CVE-2026-27483: MindsDB path traversal in /api/files leading to RCE

CVE-2026-27483 · Severity: high · CVSS 8.8 · Published 2026-02-24

Technologies: mindsdb (PyPI). Vendors: PyPI.

Executive brief

MindsDB, an open-source platform for building AI from enterprise data, contains a vulnerability in its file upload interface. An authenticated attacker can use this flaw to write or overwrite sensitive files on the server's filesystem. In practice, this allows an attacker to gain full control over the server by overwriting system scripts and executing arbitrary commands, potentially leading to data theft or complete service disruption.

Technical details

A path traversal vulnerability exists in the 'Upload File' module of MindsDB, specifically within the PUT method of the /api/files endpoint in mindsdb/api/http/namespaces/file.py. The application fails to sanitize the 'filename' parameter in multipart/form-data requests, allowing the use of '../' sequences to write files outside the intended temporary directory. An authenticated attacker can exploit this to overwrite critical Python library files (such as pip's __init__.py). By subsequently triggering a handler installation via the /<handler_name>/install endpoint, which invokes pip via subprocess.Popen, the attacker can execute arbitrary Python code with the privileges of the MindsDB process. This issue is fixed in version 25.9.1.1.

Affected products

  • MindsDB mindsdb < 25.9.1.1

Timeline

  • 2026-02-22: disclosed: Vulnerability published in mindsdb/minds repository
  • 2026-02-24: advisory: GitHub Advisory and NVD entry published
  • 2026-02-24: patched: Version 25.9.1.1 released

References

Related threats