PT-2026-36729 · Mindsdb · Mindsdb
Nn0Nkey
·
Published
2026-05-03
·
Updated
2026-05-04
·
CVE-2026-7712
CVSS v2.0
6.5
Medium
| Vector | AV:N/AC:L/Au:S/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
MindsDB versions prior to 26.01
Description
A remote deserialization issue exists within the Pickle Handler component. The flaw occurs during the execution of the
pickle.loads() function, allowing an attacker to manipulate data to achieve deserialization.Recommendations
Update to a version later than 26.01.
As a temporary workaround, restrict the use of the
pickle.loads() function within the Pickle Handler component.Exploit
Fix
RCE
Deserialization of Untrusted Data
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Mindsdb