Skip to content
PandasAIGHSA-5g73-69p4-7gvx

Code execution in pandasai

Critical9.8CVE-2024-23752 · Published Jan 22, 2024 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
pandasai
PyPI
<= 1.5.17No fix yet
Details and references

GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-862, CWE-94
Also known as
CVE-2024-23752, PYSEC-2026-446

More PandasAI advisories

All PandasAI
DateAdvisory
Aug 212023pandasai vulnerable to prompt injection
CVE-2023-39660Highfixed in 0.8.1
Aug 152023PandasAI vulnerable to arbitrary code execution
CVE-2023-39661Critical9.8no fix yet
Feb 112025PandasAI interactive prompt function Remote Code Execution (RCE)
CVE-2024-12366Critical9.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.