A critical vulnerability tracked as CVE-2026-73678 allows unauthenticated remote code execution in MindsDB Minds Platform v26.1.0 and earlier. The flaw stems from the exposed POST /api/v1/responses/ endpoint, which can route attacker-controlled prompts to the Anton agent's scratchpad tool, where Python source is executed through exec() without sandboxing. Attackers can chain this with the unauthenticated PUT /api/v1/settings/ endpoint to set their own LLM API key and then run arbitrary Python and operating system commands as the application process or desktop user.
The issue is classified as CWE-94 and was assigned the maximum severity with CVSS v3.1 10.0 and CVSS v4.0 10.0 in one disclosure, reflecting network-based exploitation with no required privileges or user interaction and full impact on confidentiality, integrity, and availability. Successful compromise could expose SSH keys, stored credentials, and environment secrets, and enable complete system takeover in the application's context. At disclosure, no vendor patch and no confirmed in-the-wild exploitation were reported; recommended mitigations included restricting external API access, placing the service behind an authenticating reverse proxy, disabling or firewalling the vulnerable endpoints, tightening CORS, and isolating the platform runtime.

Track how attackers are adapting to this technology.
3 events from the most recent confirmed update back to the earliest known activity.
The CVE entry for CVE-2026-73678 was received by disclosure@vulncheck.com. The vulnerability concerns an unauthenticated remote code execution flaw in MindsDB Minds Platform.
At the time of disclosure, no vendor patch had been published for CVE-2026-73678. Reporting also stated that no active exploitation was known at that time.
CVE-2026-73678 was disclosed as a critical unauthenticated remote code execution vulnerability affecting MindsDB Minds Platform 26.1.0 and earlier. The flaw allows attackers to set an LLM API key via an unauthenticated settings endpoint and then trigger arbitrary Python and OS command execution through the Anton agent's scratchpad exec() path.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
Follow how adversaries are adapting to this technology, and where it touches your stack today.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.