Skip to content
PandasAIGHSA-vv2h-2w3q-3fx7

PandasAI interactive prompt function Remote Code Execution (RCE)

Critical9.8CVE-2024-12366 · Published Feb 11, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
pandasai
PyPI
<= 2.4.2No fix yet
Details and references

PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM. The security controls of PandasAI (2.4.3 and earlier) fail to distinguish between legitimate and malicious inputs, allowing the attackers to manipulate the system into executing untrusted code, leading to untrusted code execution (RCE), system compromise, or pivoting attacks on connected services.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2024-12366, PYSEC-2026-448

More PandasAI advisories

All PandasAI
DateAdvisory
Jan 222024Code execution in pandasai
CVE-2024-23752Critical9.8no fix yet
Aug 212023pandasai vulnerable to prompt injection
CVE-2023-39660Highfixed in 0.8.1
Aug 152023PandasAI vulnerable to arbitrary code execution
CVE-2023-39661Critical9.8no fix yet

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.