cve/2024/CVE-2024-45853.md
2025-09-29 21:09:30 +02:00

737 B
Raw Permalink Blame History

CVE-2024-45853

Description

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded inhouse model to run arbitrary code on the server when used for a prediction.

POC

Reference

No PoCs from references.

Github