Skip to content
PandasAIGHSA-w832-v3c6-m6rg

pandasai vulnerable to prompt injection

HighCVE-2023-39660 · Published Aug 21, 2023 · updated Jul 7, 2026

An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

GitHub advisory

Affected versions

PackageAffectedFixed in
pandasai
PyPI
< 0.8.10.8.1
Details and references

More PandasAI advisories

All PandasAI
Advisory
PandasAI interactive prompt function Remote Code Execution (RCE)
Critical9.8Feb 11, 2025
Code execution in pandasai
Critical9.8Jan 22, 2024
PandasAI vulnerable to arbitrary code execution
Critical9.8Aug 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.