
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2025-68472 is an unauthenticated path traversal vulnerability in MindsDB's file upload API that allows any caller to read arbitrary files from the server filesystem and move them into MindsDB's storage, exposing sensitive data. It affects all MindsDB versions prior to 25.11.1 and was discovered by BlueRock security researchers (credited to locus-x64). The advisory was published on January 11, 2026, with NVD enrichment completed by January 27, 2026. NVD assigns a CVSS v3.1 base score of 9.1 (Critical), while the CNA (GitHub) scores it 8.1 (High) (Github Advisory, MindsDB Advisory).
The root cause is improper path sanitization (CWE-22, CWE-23, CWE-36) in the PUT handler within file.py. When the request body is JSON and source_type is not "url", the handler directly constructs a filesystem path via file_path = os.path.join(temp_dir_path, data["file"]) without any call to clear_filename or equivalent sanitization. Because Python's os.path.join ignores the base directory when given an absolute path (e.g., /etc/passwd), an attacker can target arbitrary filesystem locations. The resulting path is passed to ca.file_controller.save_file(), which reads the file contents, and a subsequent shutil.move() call relocates the victim file into MindsDB's managed storage — effectively destroying the original. A public PoC is available in the security advisory (MindsDB Advisory, BlueRock Blog).
Successful exploitation allows an unauthenticated attacker to read and exfiltrate any file accessible to the MindsDB process, including credentials, configuration secrets, private keys, and other sensitive data. Additionally, because the handler moves (not copies) the targeted file into MindsDB's storage, the original file is deleted from its source location, creating a denial-of-service condition for the affected system. The combination of data exfiltration and file destruction poses severe risks to both confidentiality and availability of the host system (MindsDB Advisory, Github Advisory).
A public proof-of-concept exploit is included in the official security advisory and requires no authentication, no special privileges, and no user interaction. The EPSS score is approximately 0.353% (58th percentile), indicating moderate exploitation probability. No in-the-wild exploitation or threat actor attribution has been reported as of the advisory date. The vulnerability is not currently listed in the CISA KEV catalog. Emerging Threats released detection rules for this CVE on January 14, 2026 (Github Advisory, Emerging Threats).
/api/files/<file_name> using an HTTP PUT request with a JSON body (Content-Type: application/json)."file" key set to either a relative traversal path (e.g., "../../../../../etc/passwd") or an absolute path (e.g., "/etc/shadow"). Omit the source_type field or set it to anything other than "url" to hit the vulnerable code branch.PUT /api/files/exfil_target with the crafted JSON payload. The server reads the targeted file and moves it into MindsDB's storage.POST /api/sql/query with body {"query": "SELECT * FROM files.exfil_target"}. The response returns the file contents./etc/shadow, application config files, SSH private keys, database credentials) (MindsDB Advisory)./api/files/<name> with Content-Type: application/json containing path traversal sequences (../ or absolute paths like /etc/) in the request body; subsequent POST requests to /api/sql/query querying files.<name> immediately after a PUT./api/files/ endpoints from unauthenticated sources; entries referencing file paths outside the MindsDB data directory in application logs./etc/passwd, config files, key files) that have been relocated to MindsDB's managed storage directory; unexpected files appearing in MindsDB's storage directory with names matching sensitive system files.python) performing unexpected file read/move operations on system files outside its normal data directories (MindsDB Advisory, Emerging Threats).Upgrade MindsDB to version 25.11.1 or later, which includes the fix for this vulnerability (MindsDB Release). For systems that cannot be immediately upgraded, implement network-level access controls (firewall rules, API gateway policies) to restrict access to the MindsDB REST API (port 47334) to trusted hosts only. Additionally, monitor for suspicious PUT requests to /api/files/ endpoints containing path traversal patterns (../ or absolute paths) in JSON payloads as a detection measure (Github Advisory).
The vulnerability was discovered and reported by BlueRock security researchers (credited to locus-x64), who published a detailed technical write-up on their blog. The CVE appeared in multiple trending CVE lists on Reddit's r/CVEWatch for January 14–16, 2026, indicating notable community interest. Emerging Threats added detection rules for this vulnerability in their ruleset update on January 14, 2026, and Check Point also published an advisory (Emerging Threats, BlueRock Blog).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."