PT-2026-36729 · Mindsdb · Mindsdb

Nn0Nkey

·

Published

2026-05-03

·

Updated

2026-05-04

·

CVE-2026-7712

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions MindsDB versions prior to 26.01
Description A remote deserialization issue exists within the Pickle Handler component. The flaw occurs during the execution of the pickle.loads() function, allowing an attacker to manipulate data to achieve deserialization.
Recommendations Update to a version later than 26.01. As a temporary workaround, restrict the use of the pickle.loads() function within the Pickle Handler component.

Exploit

Fix

RCE

Deserialization of Untrusted Data

Weakness Enumeration

Related Identifiers

CVE-2026-7712

Affected Products

Mindsdb