

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload …
Published:
11 januari 2026 om 23:00:00
Alert date:
12 januari 2026 om 18:02:27
Source:
nvd.nist.gov
Enterprise Applications, Web Technologies
CVE-2025-68472 is an unauthenticated path traversal vulnerability in MindsDB's file upload API that allows attackers to read arbitrary files from the server filesystem. The vulnerability exists in the PUT handler in file.py which directly joins user-controlled data into filesystem paths for JSON uploads without proper sanitization. Only multipart and URL-sourced uploads receive proper validation through clear_filename checks, while JSON uploads bypass these security measures entirely. This allows any unauthenticated caller to access sensitive data by moving arbitrary server files into MindsDB's storage. The vulnerability affects all versions prior to 25.11.1 and has been patched in the latest release.
Technical details
Mitigation steps:
Affected products:
MindsDB
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2025-68472
https://github.com/mindsdb/mindsdb/security/advisories/GHSA-qqhf-pm3j-96g7
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.

