{"id":"CVE-2024-5826","aliases":[],"url":"https://o3.security/vulnerability/CVE-2024-5826","summary":"In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing…","details":"In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing LLM-generated code, allowing an attacker to manipulate the code executed by the `exec` function in `src/vanna/base/base.py`. This vulnerability can be exploited by an attacker to achieve remote code execution on the app backend server, potentially gaining full control of the server.","published":"2024-06-27T19:15:17.350","modified":"2026-06-17T08:16:43.470","cvss":{"score":9.8,"severity":"CRITICAL","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://huntr.com/bounties/90620087-44ac-4e43-b659-3c5d30889369"},{"type":"WEB","url":"https://huntr.com/bounties/90620087-44ac-4e43-b659-3c5d30889369"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-06-17T08:16:43.470"}}