VannaGHSA-6mj8-jmp2-g8q7
Vanna has a SQL injection in the remove_training_data function
Medium7.3CVE-2026-4229 · Published Mar 16, 2026 · updated Jul 13, 2026
A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vector.py. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| vanna PyPI | <= 2.0.2 | No fix yet |
Details and references
More Vanna advisories
All Vanna| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jul 52024 | Vanna vulnerable to SQL Injection | High7.5 | No fix yet |
| Jun 272024 | vanna vulnerable to remote code execution caused by prompt injection | Critical9.8 | No fix yet |
| May 312024 | Vanna prompt injection code execution | Critical8.1 | No fix yet |