← Back

Gabrieleventuri

gabrieleventuri

4 CVEs • 1 product

Products (1)

Click to collapse
Toggle
Pandasai
pandasai

CVEs (4)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gabrieleventuri
1Pandasai
Apr 6, 2026
Apr 1, 2026
N/A· v4
7.3 HIGH· v3
N/A· v2
pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component.
1Gabrieleventuri
1Pandasai
May 30, 2025
Jan 22, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a data...Show more
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.Show less
1Gabrieleventuri
1Pandasai
Nov 21, 2024
Aug 21, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.
1Gabrieleventuri
1Pandasai
Nov 21, 2024
Aug 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.