Sunday, 13 September 2026
8 agent hacks today 7 vs yesterday (1)

MindsDB Minds Platform unauthenticated RCE via scratchpad tool

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability allowing attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected API endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python code without sandboxing.

Disclosed 14 August 2026 · Record updated 13 September 2026

Impact

Unauthenticated attackers can execute arbitrary OS commands as the user running the desktop application, enabling access to SSH keys, stored credentials, and environment secrets.

Our coverage

No articles linked to this incident yet.

Sources

  1. nvd.nist.govhttps://nvd.nist.gov/vuln/detail/CVE-2026-73678