PandasAIGHSA-w832-v3c6-m6rg
pandasai vulnerable to prompt injection
HighCVE-2023-39660 · Published Aug 21, 2023 · updated Jul 7, 2026
An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| pandasai PyPI | < 0.8.1 | 0.8.1 |
Details and references
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2023-39660, PYSEC-2026-1757
More PandasAI advisories
All PandasAI| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Feb 112025 | PandasAI interactive prompt function Remote Code Execution (RCE) | Critical9.8 | No fix yet |
| Jan 222024 | Code execution in pandasai | Critical9.8 | No fix yet |
| Aug 152023 | PandasAI vulnerable to arbitrary code execution | Critical9.8 | No fix yet |