Vanna-ai
Vanna-ai Vanna: vulnerabilidades y CVE
Vanna-ai Vanna tiene 12 vulnerabilidades publicadas, 8 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE12
Últimos 12 meses8
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-6977 | Media (5.5) | 0.47% | — | 25 abr 2026 | A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The manipulation leads to improper authorization. It is possible… |
| CVE-2026-5321 | Baja (2.1) | 0.19% | — | 2 abr 2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. Affected by this issue is some unknown functionality of the component FastAPI/Flask Server. Executing a manipulation can lead to permissive cross-domain policy with… |
| CVE-2026-5320 | Media (5.5) | 0.65% | — | 2 abr 2026 | A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is an unknown functionality of the file /api/vanna/v2/ of the component Chat API Endpoint. Performing a manipulation results in… |
| CVE-2026-4513 | Baja (2.1) | 0.32% | — | 21 mar 2026 | A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py. Performing a manipulation results in sql injection. The attack is… |
| CVE-2026-4511 | Baja (2.1) | 0.39% | — | 21 mar 2026 | A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed remotely. The… |
| CVE-2026-4231 | Media (5.5) | 0.47% | — | 16 mar 2026 | A vulnerability was found in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function update_sql/run_sql of the file src/vanna/legacy/flask/__init__.py of the component Endpoint. Performing a… |
| CVE-2026-4230 | Baja (2.1) | 0.32% | — | 16 mar 2026 | A vulnerability has been found in vanna-ai vanna up to 2.0.2. Affected is the function update_sql of the file src/vanna/legacy/flask/__init__.py of the component Endpoint. Such manipulation leads to sql injection. The… |
| CVE-2026-4229 | Media (5.5) | 0.41% | — | 16 mar 2026 | A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vector.py. This manipulation of the argument ID causes sql injection. The… |
| CVE-2024-8099 | Alta (8.3) | 0.35% | — | 20 mar 2025 | A Server-Side Request Forgery (SSRF) vulnerability exists in the latest version of vanna-ai/vanna when using DuckDB as the database. An attacker can exploit this vulnerability by submitting crafted SQL queries that… |
| CVE-2024-6841 | Media (6.5) | 0.24% | — | 20 mar 2025 | A Cross-Site Request Forgery (CSRF) vulnerability exists in the latest commit (56b782bcefd2e59b19cd7ba7878b95f54884f502) of the vanna-ai/vanna repository. Two endpoints in the built-in web app that provide SQL… |
| CVE-2024-5753 | Alta (7.5) | 0.60% | — | 5 jul 2024 | vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim… |
| CVE-2024-5826 | Crítica (9.8) | 0.88% | — | 27 jun 2024 | In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing LLM-generated code, allowing an… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.