PandasAIGHSA-5g73-69p4-7gvx
Code execution in pandasai
Critical9.8CVE-2024-23752 · Published Jan 22, 2024 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pandasai PyPI | <= 1.5.17 | No fix yet |
Details and references
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.
More PandasAI advisories
All PandasAI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 212023 | pandasai vulnerable to prompt injection CVE-2023-39660Highfixed in 0.8.1 | High | 0.8.1 |
| Aug 152023 | PandasAI vulnerable to arbitrary code execution CVE-2023-39661Critical9.8no fix yet | Critical9.8 | No fix yet |
| Feb 112025 | PandasAI interactive prompt function Remote Code Execution (RCE) CVE-2024-12366Critical9.8no fix yet | Critical9.8 | No fix yet |