CVE-2024-45856
A cross-site scripting (XSS) vulnerability exists in all versions of the MindsDB platform, enabling the execution of a JavaScript payload whenever a user enumerates an ML Engine, database, project, or dataset containing arbitrary JavaScript code within the web UI.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://nvd.nist.gov/vuln/detail/CVE-2024-45856, https://hiddenlayer.com/sai-security-advisory/2024-09-mindsdb, https://pypi.org/project/mindsdb, https://github.com/advisories/GHSA-32fj-r8qw-r8w8