MindsDB Minds Platform unauthenticated RCE via scratchpad tool
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability allowing attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected API endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python code without sandboxing.
Disclosed 14 August 2026 · Record updated 13 September 2026
Impact
Unauthenticated attackers can execute arbitrary OS commands as the user running the desktop application, enabling access to SSH keys, stored credentials, and environment secrets.
Our coverage
No articles linked to this incident yet.
Sources
- nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73678
