A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
CVE-2026-7712 is a deserialization vulnerability in MindsDB up to version 26.01 affecting the Pickle Handler component, allowing remote code execution through malicious pickle objects. The vulnerability has public exploits available and the vendor has not responded to disclosure attempts.
تؤثر هذه الثغرة على معالج Pickle في MindsDB حتى الإصدار 26.01 وتسمح بإلغاء تسلسل الكائنات الضارة. يمكن استغلال الثغرة عن بعد دون مصادقة، مما يؤدي إلى تنفيذ أوامر تعسفية على الخادم. تم الكشف عن الاستغلال علناً والبائع لم يستجب للإفصاح.
This vulnerability in MindsDB's pickle deserialization functionality can be exploited remotely to execute arbitrary code on affected systems. Organizations using MindsDB for data processing and AI operations should immediately patch to versions beyond 26.01.
Immediately upgrade MindsDB to version 26.02 or later. Implement network segmentation to restrict access to MindsDB instances. Disable pickle-based serialization if alternative serialization methods are available. Monitor for suspicious pickle deserialization activities in logs.
قم بترقية MindsDB فوراً إلى الإصدار 26.02 أو أحدث. طبق تقسيم الشبكة لتقييد الوصول إلى مثيلات MindsDB. عطّل التسلسل القائم على pickle إن أمكن. راقب أنشطة إلغاء التسلسل المريبة في السجلات.