Impact
MindsDB versions through 26.1.0 expose a server‑side request forgery flaw in the web crawler handler, allowing attackers to supply arbitrary URLs to CrawlerTable.list without authentication. By manipulating the caller‑controlled URLs and exploiting the default empty configuration, an attacker can bypass the allowlist control and retrieve data from any reachable address, including internal services and cloud metadata endpoints. This vulnerability can lead to unintended data disclosure, internal network exploration, or further compromise of connected services. The flaw aligns with CWE‑918, which focuses on SSRF weaknesses.
Affected Systems
Any deployment of MindsDB up to and including version 26.1.0 is affected. The vulnerability is present in all builds that have not applied the configuration changes or upgrade released after 26.1.0.
Risk and Exploitability
The vulnerability carries a CVSS score of 8.7, indicating high severity. The EPSS score is not available, and the issue is not listed in the CISA KEV catalog. Attackers can exploit the flaw via unauthenticated HTTP requests to the web crawler endpoint; no special privileges or credentials are required. As a result, the risk remains high until the issue is mitigated through patching or configuration measures.
OpenCVE Enrichment