Impact
Vanna 2.0.2 contains a code injection flaw in the VannaBase.get_plotly_figure method. The vulnerability allows an attacker to insert arbitrary code or system commands through the "exposed entry" parameter, enabling execution of code on the host running the Vanna service.
Affected Systems
Any deployment of vanna 2.0.2 that exposes the get_plotly_figure functionality to external input is vulnerable. No vendor or product cpes are listed, but the flaw exists in the Python package and would affect any web or API service that incorporates it.
Risk and Exploitability
The flaw carries a high potential impact, as it can lead to full code execution. Current data shows the EPSS score is not available and the issue is not listed in the CISA KEV catalog, so known exploitation activity is not documented. The likely attack vector is remote, via crafted input to an exposed API or user interface, and exploitation requires the attacker to control the entry parameter. The severity is inferred to be high, but the actual likelihood cannot be quantified with the current information.
OpenCVE Enrichment