Reference page — cumulative record through Wednesday, August 19, 2026 UTC. Reference pages update as the archive grows; only dated daily editions are immutable pages of record.
MindsDB Minds Platform v26.1.0 Unauthenticated RCE via scratchpad exec()
AV AC AT PR UI VC VI VA CVSS EPSS %ile KEV
N L N N N H H H 10.0 .0082 54.3 —
AFFECTED
Product Versions Fixed
Minds Platform unspecified —
TIMELINE
Aug 13 EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.
Aug 13 Reserved by VulnCheck
Aug 14 Published (CNA: VulnCheck)
Aug 16 EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added.
Description
MindsDB Minds Platform version 26.1.0 and earlier contains an unauthenticated remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary OS commands by submitting crafted prompts to the unprotected POST /api/v1/responses/ endpoint, which reaches the Anton agent's scratchpad tool that calls exec() on attacker-influenced Python source without sandboxing. Attackers can first configure their own LLM API key through the unauthenticated PUT /api/v1/settings/ endpoint, then POST a prompt directing the agent to invoke the scratchpad tool with arbitrary Python code, achieving full OS command execution as the user running the desktop application and enabling access to SSH keys, stored credentials, and environment secrets.
Lifecycle
Complete event history — 4 events, chronological
| Date | Event | Detail |
| August 13, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added. |
| August 13, 2026 | Reserved | Reserved by VulnCheck |
| August 14, 2026 | Published | Published (CNA: VulnCheck) |
| August 16, 2026 | EXPLOIT PUBLISHED | EXPLOIT PUBLISHED — CVE-2026-73678 (MindsDB Minds Platform). Public exploit reference added. |
Affected
Affected products and packages — 1 row
| Vendor | Product / Package | Ecosystem | Version introduced | Fixed |
| MindsDB | Minds Platform | — | — | — |
About this page
This is a reference page, not a dated page of record. It assembles the complete lifecycle of CVE-2026-73678 from the CVE Program record, NVD enrichment, the CISA KEV catalog, EPSS, and OSV advisories. The box score's numbers (CVSS, EPSS, KEV status) are current as of Wednesday, August 19, 2026 UTC and are re-derived as the archive grows; only dated daily editions are immutable pages of record. The authoritative source for this identifier is cve.org.