AUGUST 15, 2026
Live Feed
Back to database
Case File

CVE-2026-73678

CRITICAL · CVSS 10 Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-14 · Last synced 2026-08-15

CyberRota Analysis

AI-Generated

MindsDB Minds Platform versions 26.1.0 and earlier are vulnerable to unauthenticated remote code execution, allowing attackers to execute arbitrary OS commands via crafted prompts sent to an exposed API endpoint. This critical vulnerability enables attackers to configure their own LLM API key and leverage the scratchpad tool to run malicious Python code, potentially compromising sensitive data such as SSH keys and stored credentials. Organizations using affected versions should prioritize immediate patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
remote code execution code execution

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-73678
Severity
CRITICAL
CVSS
10
EPSS
N/A

Original NVD Description

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code, achieving full OS command execution as the user running the desktop application and enabling access to SSH keys, stored credentials, and environment secrets.