MindsDB exposes unauthenticated remote code execution through its AI agent
CVE-2026-73678, scored CVSS 10, lets an attacker with no account run system commands on the MindsDB platform through the Anton agent’s scratchpad tool. If you expose a MindsDB instance, cut public access before even waiting for a patch.