CVE-2026-73678 is a critical unauthenticated remote code execution vulnerability affecting MindsDB Minds Platform version 26.1.0 and earlier. The flaw exists because the platform exposes an unauthenticated responses API that allows attacker-controlled prompts to reach the Anton agent’s scratchpad tool, which executes attacker-influenced Python code via exec() without sandboxing or effective execution restrictions. An attacker can also use an unauthenticated settings API to configure an LLM provider key under their control and then submit crafted prompts that cause the agent to invoke the scratchpad with arbitrary Python. This results in arbitrary operating system command execution in the security context of the user running the application. The issue is fundamentally a code-injection condition in the scratchpad execution path, with missing authentication on the exposed API endpoints acting as a key enabler.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos.
This repository is a small, focused exploit PoC for CVE-2026-73678 affecting MindsDB Minds Platform (now mindshub). It contains two files: a README documenting the vulnerability, exploitation chain, impact, and usage; and a single Python exploit script, poc_cve-2026-73678.py, which is the operational entry point. The Python code uses only standard-library modules (argparse, json, time, urllib) and performs three main stages: (1) unauthenticated configuration overwrite via multiple PUT requests to /api/v1/settings/* to inject an attacker-controlled OpenAI-compatible API key, base URL, provider, and model; (2) a POST to /api/v1/responses/ with a crafted prompt intended to make the target invoke the built-in scratchpad tool with exec behavior; and (3) basic verification by checking response output and noting that /tmp/system_info.txt should exist on the target. The exploit’s core capability is unauthenticated remote code execution through prompt-driven abuse of the target’s scratchpad exec path after attacker-controlled LLM settings are installed. It also highlights an additional unauthenticated secret disclosure endpoint, /api/v1/settings/reveal-key/openai_api_key, and mentions /api/v1/settings/raw as another risky surface. The repository is a real exploit rather than a detector: it actively modifies target configuration and triggers code execution, but it remains a PoC/operational script rather than a framework-integrated or heavily weaponized tool.
This repository is a small standalone exploit PoC for CVE-2026-73678 affecting MindsDB Minds Platform / MindsHub Cowork. It contains two files: a README describing the vulnerability chain and usage, and a single Python entry point, shell.py, implementing the exploit. The code is not part of a larger exploitation framework. The exploit chains multiple unauthenticated web API weaknesses in the cowork-server sidecar. First, it uses unauthenticated PUT requests to /api/v1/settings/{field} to plant attacker-controlled LLM configuration, including an attacker-owned API key, provider selection, model names, and upstream base URL. It then calls /api/v1/settings/validate and submits a crafted prompt to POST /api/v1/responses/. That prompt instructs the Anton agent to use its scratchpad execution capability to run attacker-supplied Python. The injected Python launches arbitrary shell commands through sh -c, captures stdout/stderr, and writes a nonce plus output to /tmp/RCE_PROOF.txt on the victim host. Operationally, shell.py provides an interactive command loop. Each operator command is embedded into a Python snippet, sent through the agent prompt, and executed remotely if the vulnerable scratchpad exec path is reachable. The script includes basic retry logic for 429/rate-limit responses and verifies execution by checking whether /tmp/RCE_PROOF.txt was updated and reading back the command output. This makes the repository a real RCE exploit rather than a detector. Because the payload is functional but relatively fixed and manually driven, the maturity is best classified as OPERATIONAL.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
6 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Critical unauthenticated remote code execution vulnerability in MindsDB Cowork / Minds Platform caused by a combination of missing authentication on local API endpoints, permissive CORS, and unsafe exec()-based code execution in the Anton agent scratchpad.
A critical unauthenticated remote code execution vulnerability in MindsDB Minds Platform versions 26.1.0 and earlier that allows arbitrary OS command execution via crafted prompts reaching the Anton AI agent scratchpad tool, which executes attacker-controlled Python through exec() without sandboxing.
An unauthenticated remote code execution vulnerability in MindsDB Minds Platform 26.1.0 and earlier that allows arbitrary OS command execution via crafted prompts reaching the Anton agent scratchpad tool, which executes attacker-influenced Python code without sandboxing.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.