Security Advisory

CVE-2024-45855

7.1
HIGH

Vulnerability Description

Deserialization of untrusted data can occur in versions 23.10.2.0 and newer of the MindsDB platform, enabling a maliciously uploaded ‘inhouse’ model to run arbitrary code on the server when using ‘finetune’ on it.
Published Date September 12, 2024
Official Source NIST NVD Advisory