top of page
perceptive_background_267k.jpg

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload …

Published:

11 January 2026 at 23:00:00

Alert date:

12 January 2026 at 18:02:27

Source:

nvd.nist.gov

Click to open the original link from this advisory

Enterprise Applications, Web Technologies

CVE-2025-68472 is an unauthenticated path traversal vulnerability in MindsDB's file upload API that allows attackers to read arbitrary files from the server filesystem. The vulnerability exists in the PUT handler in file.py which directly joins user-controlled data into filesystem paths for JSON uploads without proper sanitization. Only multipart and URL-sourced uploads receive proper validation through clear_filename checks, while JSON uploads bypass these security measures entirely. This allows any unauthenticated caller to access sensitive data by moving arbitrary server files into MindsDB's storage. The vulnerability affects all versions prior to 25.11.1 and has been patched in the latest release.

Technical details

Mitigation steps:

Affected products:

MindsDB

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Disclaimer: Deze website toont informatie afkomstig van externe bronnen. Perceptive aanvaardt geen verantwoordelijkheid voor de inhoud, juistheid of volledigheid van deze informatie.

bottom of page