Safety vulnerability ID: 73321
The information on this page was manually curated by our Cybersecurity Intelligence Team.
MindsDB affected versions contain a critical vulnerability in the 'finetune' function of 'inhouse' models. This flaw allows attackers to execute arbitrary code on the server by exploiting unsafe deserialization of untrusted data. Malicious actors can upload a specially crafted 'inhouse' model, which, when finetuned, triggers the execution of arbitrary code. This vulnerability poses a significant security risk, potentially leading to unauthorized access, data breaches, or complete system compromise. Users should exercise extreme caution when finetuning 'inhouse' models and ensure they only use trusted and verified models until a patch is available.
Latest version: 24.11.4.0
MindsDB's AI SQL Server enables developers to build AI tools that need access to real-time data to perform their tasks
This vulnerability has no description
Scan your Python project for dependency vulnerabilities in two minutes
Scan your application