{"id":"CVE-2024-5826","aliases":["PYSEC-2026-562"],"url":"https://o3.security/vulnerability/CVE-2024-5826","summary":"vanna vulnerable to remote code execution caused by prompt injection","details":"In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing LLM-generated code, allowing an attacker to manipulate the code executed by the `exec` function in `src/vanna/base/base.py`. This vulnerability can be exploited by an attacker to achieve remote code execution on the app backend server, potentially gaining full control of the server.","published":"2024-06-27T21:32:08Z","modified":"2026-06-29T12:26:37.506344567Z","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"vanna","fixedVersion":null}],"fix":null,"references":[{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-5826"},{"type":"PACKAGE","url":"https://github.com/vanna-ai/vanna"},{"type":"WEB","url":"https://huntr.com/bounties/90620087-44ac-4e43-b659-3c5d30889369"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-06-29T12:26:37.506344567Z"}}