CVE-2026-73678: MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submittin...

Added to the CISA Known Exploited Vulnerabilities catalog on 14 Aug 2026. Vendor: AI/ML. Product: LLM. CVSS score: 10.

MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent...

Required action: Review and patch if applicable to your AI infrastructure.