Skip to content
VannaGHSA-mwxm-35f8-6vg2

Vanna vulnerable to SQL Injection

High7.5CVE-2024-5753 · Published Jul 5, 2024 · updated Jul 7, 2026

vanna-ai/vanna version v0.3.4 is vulnerable to SQL injection in some file-critical functions such as `pg_read_file()`. This vulnerability allows unauthenticated remote users to read arbitrary local files on the victim server, including sensitive files like `/etc/passwd`, by exploiting the exposed SQL queries via a Python Flask API.

GitHub advisory

Affected versions

PackageAffectedFixed in
vanna
PyPI
<= 0.3.4No fix yet
Details and references
CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Severity from
GitHub (reviewed advisory)
Weakness
CWE-200, CWE-89
Also known as
CVE-2024-5753, PYSEC-2026-2002

More Vanna advisories

All Vanna
Advisory
Vanna has a SQL injection in the remove_training_data function
Medium7.3Mar 16
vanna vulnerable to remote code execution caused by prompt injection
Critical9.8Jun 27, 2024
Vanna prompt injection code execution
Critical8.1May 31, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.