Skip to content
PandasAIGHSA-8fp9-43pw-56vw

PandasAI vulnerable to arbitrary code execution

Critical9.8CVE-2023-39661 · Published Aug 15, 2023 · updated Jun 29, 2026

An issue in pandas-ai v.0.8.1 and before allows a remote attacker to execute arbitrary code via the `_is_jailbreak` function.

GitHub advisory

Affected versions

PackageAffectedFixed in
pandasai
PyPI
<= 0.8.1No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-74, CWE-94
Also known as
CVE-2023-39661, PYSEC-2026-447

More PandasAI advisories

All PandasAI
Advisory
PandasAI interactive prompt function Remote Code Execution (RCE)
Critical9.8Feb 11, 2025
Code execution in pandasai
Critical9.8Jan 22, 2024
pandasai vulnerable to prompt injection
HighAug 21, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.