216.73.217.22

CVE-2024-12366

· Published 11/02/2025 13:15 · Modified 11/02/2025 20:15

Labels: CVE-2024-12366 2025-02-11CVE-2024-12366[email protected]

Essential information

Published
11/02/2025 13:15
Modified
11/02/2025 20:15
Author
Creator
CVSS
9.8 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

References