Impact
The vulnerability allows arbitrary code to be executed through the CodeExecutor.execute function in pandas-ai 3.0.0, potentially compromising confidentiality, integrity, and availability of data processed by the application. No CVSS score is provided, but the nature of the flaw suggests a high severity level by standard practice. The description does not detail the exact mechanics of the injection, so the extent of possible damage remains uncertain but could be severe.
Affected Systems
Applications that incorporate the sinaptik-ai pandas-ai 3.0.0 library are affected. The issue resides specifically in the CodeExecutor.execute component of the library, and any system that imports and calls this function is potentially vulnerable.
Risk and Exploitability
The likely attack vector is a developer or user invoking CodeExecutor.execute with malicious input; it is inferred that successful exploitation would require the ability to pass arbitrary strings to this function. Because no official CVSS metric is available, the vulnerability's calculation of risk relies on the inherent dangers of code injection. The EPSS score is not available, and the vulnerability is not listed in CISA KEV, yet the absence of these metrics does not reduce the potential for exploitation. Without a patch, the risk remains high in any environment that uses the affected library component.
OpenCVE Enrichment