

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload …
Published:
11 January 2026 at 23:00:00
Alert date:
12 January 2026 at 18:02:27
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
CVE-2025-68472 is an unauthenticated path traversal vulnerability in MindsDB's file upload API that allows attackers to read arbitrary files from the server filesystem. The vulnerability exists in the PUT handler in file.py which directly joins user-controlled data into filesystem paths for JSON uploads without proper sanitization. Only multipart and URL-sourced uploads receive proper validation through clear_filename checks, while JSON uploads bypass these security measures entirely. This allows any unauthenticated caller to access sensitive data by moving arbitrary server files into MindsDB's storage. The vulnerability affects all versions prior to 25.11.1 and has been patched in the latest release.
Technical details
Mitigation steps:
Affected products:
MindsDB
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-68472
https://github.com/mindsdb/mindsdb/security/advisories/GHSA-qqhf-pm3j-96g7
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

