{"id":"CVE-2023-39660","aliases":["GHSA-w832-v3c6-m6rg","PYSEC-2026-1757"],"title":"pandasai vulnerable to prompt injection","summary":"pandasai vulnerable to prompt injection","severity":"high","vendor":"pandasai","product":"pandasai","ecosystem":"pip","affected":["pandasai < 0.8.1"],"patched":["pandasai 0.8.1"],"published":"2023-08-21","updated":"2026-07-07","source":"OSV","sourceUrl":"https://osv.dev/vulnerability/GHSA-w832-v3c6-m6rg","references":[{"url":"https://nvd.nist.gov/vuln/detail/CVE-2023-39660"},{"url":"https://github.com/gventuri/pandas-ai/issues/399"},{"url":"https://github.com/gventuri/pandas-ai/pull/409"},{"url":"https://github.com/gventuri/pandas-ai/commit/3aac79be8fc1d18b53d66a566adddbbdd2b38ad5"},{"url":"https://github.com/gventuri/pandas-ai"}],"tags":["osv","pip"],"epss":0.01534,"epssPercentile":0.73275,"ingestedAt":"2026-07-08T18:25:53.579Z","slug":"CVE-2023-39660","body":"## Overview\n\nAn issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.\n\n## Affected packages\n\n- `pandasai < 0.8.1`\n\n## Remediation\n\nUpgrade to a patched release:\n\n- `pandasai 0.8.1`","depth":"twilight","depthScore":42,"depthScoreParts":{"impact":41.3,"likelihood":0.3,"exploitation":0,"ransomware":0},"changes":[]}