FixVibe

high

MindsDB Path Traversal in /api/files Leading to Remote Code Execution (CVE-2026-27483)

A critical path traversal vulnerability exists in the MindsDB `/api/files` endpoint. Attackers can exploit this flaw to read or write arbitrary files on the server, ultimately leading to Remote Code Execution (RCE). Users should upgrade to version 25.9.1.1 or later.

CVE-2026-27483GHSA-4894-xqv6-vrfqCWE-22

Vulnerability Overview

MindsDB versions before 25.9.1.1 are associated with a path traversal issue in the /api/files surface [S1]. In vulnerable deployments, file-path handling can allow access outside the intended storage boundary and may contribute to remote code execution when combined with application behavior [S1][S2].

Attacker Impact

Successful exploitation can expose sensitive files or allow attacker-controlled content to be placed where MindsDB will process it [S1][S2]. The practical impact depends on deployment configuration, authentication, filesystem permissions, and reachable MindsDB features.

Root Cause

The issue comes from insufficient validation of file path input in affected MindsDB releases [S1]. The fixed release tightens path handling so uploaded or referenced files cannot escape the expected directory boundary.

Remediation

Upgrade MindsDB to version 25.9.1.1 or later [S1]. Review any exposed MindsDB API endpoints, rotate secrets that may have been readable from the host, and restrict administrative/API access to trusted networks while patching.

Covered by FixVibe

FixVibe's verified active scans flag MindsDB deployments running a release line affected by this advisory, with the detected version evidence so you can upgrade to 25.9.1.1 or later.