PT-2026-86397 · Mindsdb · Mindsdb
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
MindsDB versions prior to 26.1.1
Description
A server-side request forgery (SSRF) issue exists in the web crawler handler. This allows unauthenticated attackers to fetch arbitrary URLs by providing caller-controlled URLs to the
CrawlerTable.list function. By exploiting the default empty configuration, attackers can bypass allowlist controls to access internal services and cloud metadata endpoints without authentication.Recommendations
Update MindsDB to version 26.1.1 or later.
Fix
SSRF
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Mindsdb