pandasai vulnerabilities
CVEs whose affected-version data names the pandasai package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2024-12366Critical· 9.8PandasAI interactive prompt function Remote Code Execution (RCE)
PandasAI interactive prompt function Remote Code Execution (RCE)
▾ Midnightpandasai · pandasaiEPSS 1.2%via OSV
CVE-2023-39660Highpandasai vulnerable to prompt injection
pandasai vulnerable to prompt injection
▾ Twilightpandasai · pandasaiEPSS 1.5%via OSV