Skip to content
VannaGHSA-rrqq-fv6m-692m

vanna vulnerable to remote code execution caused by prompt injection

Critical9.8CVE-2024-5826 · Published Jun 27, 2024 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
vanna
PyPI
<= 0.6.2No fix yet
Details and references

In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing LLM-generated code, allowing an attacker to manipulate the code executed by the `exec` function in `src/vanna/base/base.py`. This vulnerability can be exploited by an attacker to achieve remote code execution on the app backend server, potentially gaining full control of the server.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2024-5826, PYSEC-2026-562

More Vanna advisories

All Vanna
DateAdvisory
Jul 52024Vanna vulnerable to SQL Injection
CVE-2024-5753High7.5no fix yet
May 312024Vanna prompt injection code execution
CVE-2024-5565Critical8.1no fix yet
Mar 16Vanna has a SQL injection in the remove_training_data function
CVE-2026-4229Medium7.3no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.