MindsDB是MindsDB公司的一个专为AI代理和大语言模型设计的联合查询引擎,可以回答pb级企业数据的问题。 MindsDB 25.9.1.1之前版本存在路径遍历漏洞,该漏洞源于/api/files接口存在路径遍历,可能导致经过身份验证的攻击者通过上传文件实现远程命令执行。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| # | POC Description | Source Link | Shenlong Link |
|---|---|---|---|
| 1 | MindsDB < 25.9.1.1 contains a remote code execution caused by path traversal in the /api/files upload file module, letting authenticated attackers write arbitrary files and execute commands, exploit requires authentication. | https://github.com/projectdiscovery/nuclei-templates/blob/main/http/cves/2026/CVE-2026-27483.yaml | POC Details |
No public POC found.
Login to generate AI POCNo comments yet