{"id":"CVE-2025-24793","aliases":["GHSA-2vpq-fh52-j3wv","PYSEC-2025-26"],"url":"https://o3.security/vulnerability/CVE-2025-24793","summary":"Snowflake Connector for Python has an SQL Injection in write_pandas","details":"The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1.","published":"2025-01-29T20:23:02.227Z","modified":"2026-08-08T03:47:52.555135592Z","cvss":{"score":7,"severity":"HIGH","vector":"CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"snowflake-connector-python","fixedVersion":"3.13.1"}],"fix":{"url":"https://github.com/snowflakedb/snowflake-connector-python/commit/f3f9b666518d29c31a49384bbaa9a65889e72056","label":"snowflakedb/snowflake-connector-python@f3f9b66"},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2025/24xxx/CVE-2025-24793.json"},{"type":"ADVISORY","url":"https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-2vpq-fh52-j3wv"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2025-24793"},{"type":"FIX","url":"https://github.com/snowflakedb/snowflake-connector-python/commit/f3f9b666518d29c31a49384bbaa9a65889e72056"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-08T03:47:52.555135592Z"}}