PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.
Metrics
Affected Vendors & Products
References
History
Fri, 11 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 11 Feb 2025 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
cvssV3_1
|
Tue, 11 Feb 2025 14:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Tue, 11 Feb 2025 13:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM. | |
| Title | CVE-2024-12366 | |
| References |
|
Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-02-11T19:28:21.551Z
Reserved: 2024-12-09T14:19:01.050Z
Link: CVE-2024-12366
Updated: 2025-02-11T13:06:54.549Z
Status : Received
Published: 2025-02-11T13:15:29.193
Modified: 2025-02-11T20:15:33.247
Link: CVE-2024-12366
No data.
OpenCVE Enrichment
No data.