CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2025-68472

MindsDB's Moving Day: How a JSON Payload Evicted /etc/passwd

Amit Schendel
Amit Schendel
Senior Security Researcher

Feb 21, 2026·6 min read·57 visits

Executive Summary (TL;DR)

MindsDB versions < 25.11.1 contain an unauthenticated path traversal flaw in the file upload API. Attackers can trick the server into moving critical system files (like `/etc/passwd`) into the database storage. This deletes the file from the OS, crashing the server, while exposing its contents to the attacker via SQL.

A critical path traversal vulnerability in MindsDB allows unauthenticated attackers to not just read, but physically move arbitrary files from the server's filesystem into the database's internal storage. Due to Python's `os.path.join` behavior and a lack of input sanitization in the JSON API handler, a simple PUT request can relocate sensitive system files like `/etc/passwd`, resulting in immediate Information Disclosure and a catastrophic Denial of Service.

The Hook: AI That Knows Too Much

MindsDB is the cool kid on the block for developers who want to sprinkle some "AI magic" onto their existing databases without learning PyTorch. It acts as a virtual database, sitting between your application and your data, allowing you to run SQL queries that train models or make predictions. It’s powerful, it’s convenient, and as it turns out, it was a little too eager to help you manage your files.

Deep within the mindsdb/api/http/namespaces/file.py module lies a feature designed to let users upload datasets (CSVs, JSONs) to be used as tables. Typically, this is where you'd upload your sales history to predict next quarter's revenue. But thanks to CVE-2025-68472, this feature became a weapon of mass destruction for the local filesystem.

The vulnerability isn't just a standard "read-only" path traversal where I peek at your config files. This is a "move" operation. The application takes the file you specify and relocates it to its own internal storage. If you point it at a system file, MindsDB doesn't just read it; it evicts it. It’s the digital equivalent of a moving company showing up to the wrong house and stripping the copper wiring because someone signed a work order with the address "/root".

The Flaw: The `os.path.join` Trap

To understand this bug, you have to understand one specific quirk of Python's standard library that has bitten more developers than I can count. The function os.path.join() is supposed to intelligently combine path components. You give it a directory, a filename, and it gives you a path. Simple, right?

However, the documentation—which nobody reads until they've been hacked—states clearly: "If a component is an absolute path, all previous components are thrown away and joining continues from the absolute path component."

This means if I write:

os.path.join("/safe/temp/dir", "/etc/passwd")

Python doesn't give me /safe/temp/dir/etc/passwd. It sees that second argument starts with a slash, assumes I know what I'm doing, and returns /etc/passwd. It discards the safe directory entirely. The developers at MindsDB handled multipart/form-data uploads correctly, sanitizing filenames. But for JSON-based requests, they missed a spot. They took the input straight from the JSON body and fed it to this function. It's like locking your front door with a deadbolt but leaving the back wall missing.

The Code: The Smoking Gun

Let's look at the crime scene in mindsdb/api/http/namespaces/file.py. The handlers for standard file uploads were actually checking filenames. But the logic for handling a JSON PUT request looked something like this:

# The Vulnerable Logic
if 'file' in data:
    # data is the raw JSON body
    file_path = os.path.join(temp_dir_path, data['file'])
    # ... later ...
    shutil.move(file_path, destination)

See that? data['file'] is controlled entirely by the user. If I send {"file": "/etc/passwd"}, file_path becomes /etc/passwd. The code then proceeds to use shutil.move to relocate that file into MindsDB's storage directory.

The fix, introduced in version 25.11.1, was simple but effective. They forced the input through a sanitization function (similar to secure_filename) or essentially treated the input as a base filename rather than a path:

# The Fix (Conceptual)
filename = secure_filename(data['file'])
file_path = os.path.join(temp_dir_path, filename)

Now, if I send /etc/passwd, it gets stripped down to just passwd (or similar), and the join results in /safe/temp/dir/passwd. The attack fails because that file doesn't exist in the temp directory.

The Exploit: Evicting the Landlord

Exploiting this is terrifyingly simple. We don't need complex shellcode or heap grooming. We just need curl. Since the API endpoint was unauthenticated by default in older versions, we can walk right in.

Here is the attack chain:

  1. Recon: Identify a MindsDB instance exposing port 47334/47335.
  2. The Payload: Construct a JSON body pointing to a critical system file.
curl -X PUT http://target:47334/api/files/sys_config \
     -H "Content-Type: application/json" \
     -d '{"file": "/etc/passwd"}'
  1. The Execution:

    • The server receives the request.
    • os.path.join resolves the path to /etc/passwd.
    • shutil.move('/etc/passwd', '/var/lib/mindsdb/files/sys_config') runs.
  2. The Aftermath:

    • DoS: The Linux server now has no /etc/passwd. SSH logins fail. New processes might fail to start if they need user resolution. The system is effectively bricked until an admin boots into recovery mode.
    • Disclosure: The attacker can now query the file contents via MindsDB's SQL interface: SELECT * FROM files.sys_config.

It’s a "two-for-one" special: you steal the secrets and you destroy the server's ability to function.

The Impact: Scorched Earth

While the CVSS score sits at a high 8.1, the operational impact of this vulnerability is severe. In a standard path traversal (Information Disclosure), the victim still has their data. Here, the data is stolen and erased from its source.

Imagine an attacker targeting /var/lib/mysql/ibdata1 or a web application's config.php. They aren't just reading your database credentials; they are deleting the configuration file that makes your website work. This transforms a confidentiality breach into a high-impact availability incident.

Furthermore, because MindsDB is often deployed in containerized environments (Docker/Kubernetes), the impact might be limited to the container. However, if the container is running as root (a common sin) and has volumes mounted from the host (e.g., -v /etc:/mnt/host_etc), an attacker could potentially wipe files on the host system itself, escaping the ephemeral nature of the container.

The Fix: Stop the Bleeding

If you are running MindsDB < 25.11.1, you are vulnerable. The remediation is straightforward:

  1. Patch: Upgrade to MindsDB v25.11.1 immediately. This version introduces proper filename sanitization for JSON payloads and enforces stricter authentication checks.
  2. Network Segmentation: Never expose the MindsDB management API (ports 47334/47335) to the public internet. These should be internal-only, ideally behind a VPN or strictly allowed IPs.
  3. Least Privilege: Ensure the MindsDB process does not run as root. Create a dedicated mindsdb user with limited filesystem access. If the process can't read /etc/passwd, it can't move it.

> [!NOTE] > Even with the patch, audit your mindsdb_config.json. Ensure http_auth_enabled is set to true. Relying on "nobody knows this port is open" is not a security strategy; it's a prayer.

Official Patches

MindsDBFix commit implementing filename sanitization

Technical Appendix

CVSS Score
8.1/ 10
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:N/I:H/A:H
EPSS Probability
0.05%
Top 85% most exploited

Affected Systems

MindsDB < 25.11.1

Affected Versions Detail

Product
Affected Versions
Fixed Version
MindsDB
MindsDB
< 25.11.125.11.1
AttributeDetail
CWE IDCWE-22 (Path Traversal)
Attack VectorNetwork (API)
CVSS8.1 (High)
ImpactInfo Disclosure + Denial of Service
Vulnerable Functionos.path.join + shutil.move
Exploit StatusPoC Available

MITRE ATT&CK Mapping

T1083File and Directory Discovery
Discovery
T1005Data from Local System
Collection
T1499Endpoint Denial of Service
Impact
CWE-22
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')

The software uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the software does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Known Exploits & Detection

GitHubPython PoC exploit for MindsDB Path Traversal

Vulnerability Timeline

Public Disclosure & CVE Published
2026-01-12
Patch Released (v25.11.1)
2026-01-12

References & Sources

  • [1]MindsDB Repository

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•about 6 hours ago•GHSA-JHJP-4C2Q-XMX4
8.1

GHSA-JHJP-4C2Q-XMX4: Falco k8saudit Plugin Ruleset Bypass via initContainers and ephemeralContainers

A security feature bypass vulnerability in the Falco k8saudit plugin (and its cloud-specific variants) allowed privileged workloads to run undetected. This bypass occurred because the plugin's default extraction logic and rules only evaluated standard containers, completely omitting initContainers and ephemeralContainers.

Amit Schendel
Amit Schendel
4 views•6 min read
•about 7 hours ago•CVE-2026-61630
4.2

CVE-2026-61630: Time-Based One-Time Password (TOTP) Reuse/Replay in nginx-ignition

nginx-ignition is a web-based user interface for managing the Nginx web server. In versions 2.33.0 through 2.35.0, the application is vulnerable to an improper authentication flaw (CWE-287) in its Multi-Factor Authentication (MFA) implementation. The stateless validation of Time-Based One-Time Passwords (TOTP) allows an attacker to reuse a captured, active verification code multiple times within the standard 30-second validity window, successfully bypassing secondary authentication checks if primary credentials are known.

Amit Schendel
Amit Schendel
8 views•5 min read
•about 8 hours ago•CVE-2026-61629
7.5

CVE-2026-61629: CPU Amplification Denial of Service via ParseAcceptLanguage Underscore Bypass

A vulnerability exists in the i18n middleware of nginx-ignition, enabling CPU amplification attacks. By transmitting a crafted Accept-Language header containing malformed tags separated by underscores, an unauthenticated remote attacker can bypass the length-guard threshold of the underlying Go parsing library. Normalization of underscores to hyphens occurs after the initial validation checks, forcing the parser into expensive quadratic-time loops that consume 100% of available CPU resources. This leads to a complete denial of service for the administrative API and potentially degrades the availability of the hosting system. This vulnerability has been resolved in version 2.40.1.

Alon Barad
Alon Barad
6 views•7 min read
•about 9 hours ago•CVE-2026-61628
8.1

CVE-2026-61628: Unauthenticated Admin Account Creation via Onboarding Race Condition in Nginx Ignition

Nginx Ignition prior to version 2.41.1 contains a Time-of-Check to Time-of-Use (TOCTOU) race condition in its unauthenticated onboarding API endpoint. This flaw allows remote, unauthenticated attackers to register an administrative account by sending concurrent HTTP requests during the initial system configuration phase, bypassing the check meant to restrict onboarding to a single initial administrator.

Amit Schendel
Amit Schendel
7 views•6 min read
•about 15 hours ago•CVE-2026-61687
7.1

CVE-2026-61687: OAuth State Validation Bypass and Login CSRF in Hatchet

A logic error in Hatchet's OAuth state validation mechanism allows unauthenticated remote attackers to bypass state parameter verification. By submitting an empty state parameter, attackers can exploit an equality collision with cleared session keys, facilitating Login Cross-Site Request Forgery (Login CSRF) or Session Fixation.

Amit Schendel
Amit Schendel
10 views•10 min read
•3 days ago•CVE-2026-58197
8.8

CVE-2026-58197: Host Escape and Lateral Movement via Insecure Container Network Defaults in ToolHive

A high-severity access control vulnerability in ToolHive CLI before v0.30.1 and ToolHive Studio before v0.38.0 allows local containerized MCP servers to bypass network isolation. This enables malicious workloads to establish TCP/IP connections to administrative and control plane endpoints exposed on the host loopback interface.

Amit Schendel
Amit Schendel
12 views•8 min read