CVE-2023-49795: Mindsdb
Medium severity, CVSS 5.3. EPSS: 0.4% chance of exploitation in the next 30 days.
MindsDB connects artificial intelligence models to real time data. Versions prior to 23.11.4.1 contain a server-side request forgery vulnerability in `file.py`. This can lead to limited information disclosure. Users should use MindsDB's `staging` branch or v23.11.4.1, which contain a fix for the issue.
Affected products
- Mindsdb Mindsdb: before 23.11.4.1 (fixed in 23.11.4.1)
Published 2023-12-11. Last modified 2026-06-17.