Monitor vulnerabilities like this one.
Sign up free to get alerted when software you use is affected.
10.0
CVE-2026-73678: MindsDB Minds Platform v26.1.0: Unauthenticated Code Execution
CVE-2026-73678 · published 20 days ago
Summary
An attacker can execute any system command without a password, potentially stealing sensitive data or taking control of the system. This is a serious issue because it affects the security of sensitive data like passwords and SSH keys. To protect your system, update to the latest version of MindsDB Minds Platform.
What to do
The CVE record does not list a fixed version. Check the vendor's site or the advisory links below - a fix may already be released.
Affected software
| Vendor | Product | Affected versions |
|---|---|---|
| mindsdb | minds platform | <= 26.1.0 |
Original advisory text
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submittin...
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code, achieving full OS command execution as the user running the desktop application and enabling access to SSH keys, stored credentials, and environment secrets.
Severity
10.0
Critical
CVSS 3.1: 10.0 (NVD)
CVSS 4.0: 10.0 (NVD)
Exploitation
EPSS 1%
Type
CWE-94Code Injection
Timeline
Published14 Aug 2026
Updated30 Aug 2026
First seen14 Aug 2026
Monitor software like this
Free during beta