-
CVSS Score
-Basic Information
CVE ID
-
GHSA ID
-
EPSS Score
-
CWE
-
Published
-
Updated
-
KEV Status
-
Technology
-
The vulnerability description explicitly states that user-supplied input (e.g., ML Engine names, dataset values) is rendered without proper sanitization in the web UI. The HiddenLayer example demonstrates that raw HTML/JavaScript in dataset fields executes when rendered in the UI's table view. While the advisory does not provide exact function names or file paths (unlike other CVEs in the same report), the XSS mechanism inherently points to frontend rendering logic responsible for displaying enumerated entities. The lack of output encoding for user-controlled data in these UI components is the root cause.
| Package Name | Ecosystem | Vulnerable Versions | First Patched Version |
|---|---|---|---|
| mindsdb | pip | <= 24.9.2.1 |
Ongoing coverage of React2Shell