Description
vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Published: 2026-10-02
Score: n/a
EPSS: n/a
KEV: No
Impact: Remote Code Execution
Action: Immediate Patch
AI Analysis

Impact

Vanna 2.0.2 contains a code injection flaw in the VannaBase.get_plotly_figure method. The vulnerability allows an attacker to insert arbitrary code or system commands through the "exposed entry" parameter, enabling execution of code on the host running the Vanna service.

Affected Systems

Any deployment of vanna 2.0.2 that exposes the get_plotly_figure functionality to external input is vulnerable. No vendor or product cpes are listed, but the flaw exists in the Python package and would affect any web or API service that incorporates it.

Risk and Exploitability

The flaw carries a high potential impact, as it can lead to full code execution. Current data shows the EPSS score is not available and the issue is not listed in the CISA KEV catalog, so known exploitation activity is not documented. The likely attack vector is remote, via crafted input to an exposed API or user interface, and exploitation requires the attacker to control the entry parameter. The severity is inferred to be high, but the actual likelihood cannot be quantified with the current information.

Generated by OpenCVE AI on October 2, 2026 at 17:45 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to the latest vanna release that resolves the code injection vulnerability.
  • Ensure that all parameters passed to VannaBase.get_plotly_figure are strictly validated or sanitized, rejecting non‑trusted input.
  • Restrict access to the service or interface that exposes get_plotly_figure, allowing only trusted users or internal networks.

Generated by OpenCVE AI on October 2, 2026 at 17:45 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:00:00 +0000

Type Values Removed Values Added
First Time appeared Vanna-ai
Vanna-ai vanna
Vendors & Products Vanna-ai
Vanna-ai vanna

Fri, 02 Oct 2026 18:00:00 +0000

Type Values Removed Values Added
Title Code Injection Vulnerability in Vanna Base's Plotly Figure Generation Enabling Remote Code Execution
Weaknesses CWE-77
CWE-94

Fri, 02 Oct 2026 16:00:00 +0000

Type Values Removed Values Added
Description vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
References

cve-icon MITRE

Status: PUBLISHED

Assigner: mitre

Published:

Updated: 2026-10-02T15:41:51.184Z

Reserved: 2026-06-08T00:00:00.000Z

Link: CVE-2026-51911

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Deferred

Published: 2026-10-02T16:16:50.430

Modified: 2026-10-02T18:47:49.947

Link: CVE-2026-51911

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T18:45:17Z

Weaknesses
  • CWE-77

    Improper Neutralization of Special Elements used in a Command ('Command Injection')

  • CWE-94

    Improper Control of Generation of Code ('Code Injection')