Skip to main content
HIGH

CVE-2025-68472

MindsDB has improper sanitation of filepath that leads to information disclosure and DOS

CVSS v3

8.1

HIGH

EPSS Score

20.3 %

exploit probability, as of 2026-09-25

CISA KEV

No

known exploited

Exploitation

poc

SSVC status

Description

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing sensitive data. The PUT handler in file.py directly joins user-controlled data into a filesystem path when the request body is JSON and source_type is not "url". Only multipart uploads and URL-sourced uploads receive sanitiza

Technical details

Published
2026-01-12
Last Modified
2026-02-20

Frequently asked questions

What is CVE-2025-68472?

MindsDB is a platform for building artificial intelligence from enterprise data. Prior to version 25.11.1, an unauthenticated path traversal in the file upload API lets any caller read arbitrary files from the server filesystem and move them into MindsDB’s storage, exposing sensitive data. The PUT handler in file.py directly joins user-controlled data into a filesystem path when the request body is JSON and source_type is not "url". Only multipart uploads and URL-sourced uploads receive sanitiza

Is CVE-2025-68472 actively exploited?

A proof-of-concept exploit exists for CVE-2025-68472, but active exploitation has not been confirmed at this time.

What is the CVSS score for CVE-2025-68472?

CVE-2025-68472 has a CVSS v3 base score of 8.1 (HIGH severity).

Is CVE-2025-68472 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.

No credit card required · 500 free checks/month · Free API key