Gabrieleventuri
Gabrieleventuri Pandasai: vulnerabilidades y CVE
Gabrieleventuri Pandasai tiene 8 vulnerabilidades publicadas, 4 de ellas en los últimos 12 meses. 4 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE8
Últimos 12 meses4
Críticas4
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-30273 | Alta (7.3) | 0.30% | — | 1 abr 2026 | pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component. |
| CVE-2026-4998 | Media (5.5) | 0.67% | — | 28 mar 2026 | A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message… |
| CVE-2026-4997 | Media (5.5) | 0.77% | — | 28 mar 2026 | A security flaw has been discovered in Sinaptik AI PandasAI up to 3.0.0. This affects the function is_sql_query_safe of the file pandasai/helpers/sql_sanitizer.py. Performing a manipulation results in path traversal.… |
| CVE-2026-4996 | Media (5.5) | 0.41% | — | 28 mar 2026 | A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function… |
| CVE-2024-12366 | Crítica (9.8) | 1.2% | — | 11 feb 2025 | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language… |
| CVE-2024-23752 | Crítica (9.8) | 1.0% | — | 22 ene 2024 | GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a… |
| CVE-2023-39660 | Crítica (9.8) | 1.5% | — | 21 ago 2023 | An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function. |
| CVE-2023-39661 | Crítica (9.8) | 1.4% | — | 15 ago 2023 | An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function. |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.