id: PYSEC-2026-1629 published: "2026-07-07T14:34:40.612166Z" modified: "2026-07-07T17:24:41.184168Z" aliases: - CVE-2024-45847 - GHSA-crmg-rp64-5cm3 summary: MindsDB Eval Injection vulnerability details: An arbitrary code execution vulnerability exists in versions 23.11.4.2 up to 24.7.4.1 of the MindsDB platform, when one of several integrations is installed on the server. If a specially crafted ‘UPDATE’ query containing Python code is run against a database created with the specified integration engine, the code will be passed to an eval function and executed on the server. affected: - package: name: mindsdb ecosystem: PyPI purl: pkg:pypi/mindsdb ranges: - type: ECOSYSTEM events: - introduced: 23.11.4.2 - fixed: 24.7.4.1 versions: - 23.11.4.4a6 - 23.12.4.0 - 23.12.4.1 - 23.12.4.2 - 24.1.4.0 - 24.2.3.0 - 24.3.4.0 - 24.3.4.1 - 24.3.4.2 - 24.3.5.0 - 24.4.2.0 - 24.4.2.1 - 24.4.3.0 - 24.5.4.0 - 24.6.1.0 - 24.6.1.1 - 24.6.2.0 - 24.6.2.2 - 24.6.3.0 - 24.6.3.1 - 24.6.4.1 - 24.7.1.0 - 24.7.2.0 - 24.7.3.0 - 24.7.4.0 references: - type: ADVISORY url: https://nvd.nist.gov/vuln/detail/CVE-2024-45847 - type: WEB url: https://github.com/mindsdb/mindsdb/commit/11a4db792ad36cf704f7307c7602128b17752c80 - type: PACKAGE url: https://github.com/mindsdb/mindsdb - type: WEB url: https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb - type: PACKAGE url: https://pypi.org/project/mindsdb - type: ADVISORY url: https://github.com/advisories/GHSA-crmg-rp64-5cm3 severity: - type: CVSS_V3 score: CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H - type: CVSS_V4 score: CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N