CVE-2023-49795: Mindsdb

Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.

MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue.

Affected products

  • Mindsdb Mindsdb: before 23.11.4.1 (fixed in 23.11.4.1)

Published 2023-12-11. Last modified 2026-06-17.