PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.
Metrics
Affected Vendors & Products
References
History
Tue, 11 Feb 2025 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
cvssV3_1
|
Tue, 11 Feb 2025 14:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
|
Tue, 11 Feb 2025 13:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM. | |
Title | CVE-2024-12366 | |
References |
|

Status: PUBLISHED
Assigner: certcc
Published:
Updated: 2025-02-11T19:28:21.551Z
Reserved: 2024-12-09T14:19:01.050Z
Link: CVE-2024-12366

Updated: 2025-02-11T13:06:54.549Z

Status : Received
Published: 2025-02-11T13:15:29.193
Modified: 2025-02-11T20:15:33.247
Link: CVE-2024-12366

No data.