GHSA-32fj-r8qw-r8w8
GitHub Security Advisory
MindsDB Cross-site Scripting vulnerability
✓ GitHub Reviewed
MODERATE
Has CVE
Advisory Details
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.
Affected Packages
PyPI
mindsdb
Affected versions:
0
(last affected: 24.9.2.1)
Related CVEs
Key Information
5.0
/10
Dataset
Last updated: July 12, 2025 6:29 AM
Data from GitHub Advisory Database. This information is provided for research and educational purposes.