Impact
An SQL injection flaw exists in the update_sql function of the Endpoint component in vanna-ai vanna. An attacker can inject arbitrary SQL statements via this endpoint, potentially reading, modifying or deleting data stored in the database. The weakness is cataloged as CWE-74 and CWE-89 and can be exploited remotely without special privileges, allowing unauthorized access to sensitive information and possible disruption of database integrity.
Affected Systems
vanna-ai vanna – versions up to and including 2.0.2 are affected. No later versions are listed as vulnerable.
Risk and Exploitability
The vulnerability has a CVSS score of 5.3, indicating moderate severity. Its EPSS score is below 1%, suggesting a low probability of exploitation in the wild, and it is not listed in the CISA Known Exploited Vulnerabilities catalog. The attack vector is remote, and exploitation requires sending crafted input to the update_sql endpoint. Due to the potential for data compromise, it is advisable to address the issue promptly.
OpenCVE Enrichment