Gabrieleventuri

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 4
    Known Exploited: 0
    3
    Critical Level Threats
    1
    High Level Threats
    0
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-30273

    pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component.

    Last Modified: Apr 07, 2026
    Published: Apr 01, 2026

    CVE-2024-23752

    GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.

    Last Modified: May 30, 2025
    Published: Jan 22, 2024

    CVE-2023-39660

    An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

    Last Modified: Nov 21, 2024
    Published: Aug 21, 2023

    CVE-2023-39661

    An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.

    Last Modified: Nov 21, 2024
    Published: Aug 15, 2023
    Items Per Page