PatchSiren

MindsDB CVE debriefs

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

CRITICAL MindsDB CVE published 2026-08-14

CVE-2026-73678

CVE-2026-73678 is a critical unauthenticated remote code execution vulnerability in MindsDB Minds Platform version 26.1.0 and earlier. The vulnerability allows attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint. This CVE was published on 2026-08-14T19:18:01.457Z and was last modified on 2026-09-24T20:06:30.133Z.