vanna vulnerabilities
CVEs whose affected-version data names the vanna package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
2 CVEsRSS
CVE-2026-4229High· 7.3Vanna has a SQL injection in the remove_training_data function
Vanna has a SQL injection in the remove_training_data function
▾ Twilightvanna · vannaEPSS 0.25%via OSV
CVE-2024-5753High· 7.5Vanna vulnerable to SQL Injection
Vanna vulnerable to SQL Injection
▾ Twilightvanna · vannaEPSS 0.60%via OSV