CVE-2026-27483 - MindsDB has Path Traversal in /api/files Leading to Remote Code Execution

CVE-2026-27483 - MindsDB has Path Traversal in /api/files Leading to Remote Code Execution

CVE ID : CVE-2026-27483 Published : Feb. 24, 2026, 3:21 p.m. | 1 hour, 10 minutes ago Description : MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.9.1.1, there is a path traversal vulnerability in Mindsdb's /api/files interface, which an authenticated attacker can exploit to achieve remote command execution. The vulnerability exists in the

CVE Details

Published
Feb. 24, 2026
Impact: path traversal