Skip to content
VannaGHSA-6mj8-jmp2-g8q7

Vanna has a SQL injection in the remove_training_data function

Medium7.3CVE-2026-4229 · Published Mar 16, 2026 · updated Jul 13, 2026

A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vector.py. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

GitHub advisory

Affected versions

PackageAffectedFixed in
vanna
PyPI
<= 2.0.2No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
Severity from
GitHub (reviewed advisory)
Weakness
CWE-74, CWE-89
Also known as
CVE-2026-4229, PYSEC-2026-3397

More Vanna advisories

All Vanna
Advisory
Vanna vulnerable to SQL Injection
High7.5Jul 5, 2024
vanna vulnerable to remote code execution caused by prompt injection
Critical9.8Jun 27, 2024
Vanna prompt injection code execution
Critical8.1May 31, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.