CVE-2023-49795
Python vulnerability analysis and mitigation

Overview

MindsDB, a software that connects artificial intelligence models to real-time data, was found to contain a server-side request forgery (SSRF) vulnerability in versions prior to 23.11.4.1. The vulnerability, identified as CVE-2023-49795, was discovered in the file.py component and could lead to limited information disclosure (NVD, GitHub Advisory).

Technical details

The vulnerability exists in the put method within mindsdb/mindsdb/api/http/namespaces/file.py where user-controlled URL in the source variable is not properly validated before being used to create arbitrary requests. The issue was identified using the SSRF CodeQL query for Python. The vulnerability has been assigned a CVSS v3.1 base score of 5.3 (MEDIUM) with the vector string CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N (GitHub Lab).

Impact

The SSRF vulnerability allows for forging arbitrary network requests from the MindsDB server. It can be exploited to scan nodes in internal networks for open ports that may not be accessible externally, as well as scan for existing files on the internal network. The vulnerability enables retrieval of files with csv, xls, xlsx, json or parquet extensions, which become viewable via MindsDB GUI. For any other existing files, it functions as a blind SSRF (GitHub Lab).

Mitigation and workarounds

Users are advised to upgrade to MindsDB version 23.11.4.1 or use the staging branch, which contains the fix for this vulnerability. The fix includes implementation of proper URL validation and security checks (NVD, GitHub Advisory).

Additional resources


SourceThis report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2026-23949HIGH8.6
  • PythonPython
  • jaraco.context
NoYesJan 20, 2026
CVE-2026-22219HIGH8.3
  • PythonPython
  • chainlit
NoYesJan 20, 2026
CVE-2026-23842HIGH7.5
  • PythonPython
  • chatterbot
NoYesJan 19, 2026
CVE-2026-23877MEDIUM5.3
  • PythonPython
  • swingmusic
NoYesJan 19, 2026
CVE-2026-23833LOW1.7
  • PythonPython
  • esphome
NoYesJan 19, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management