Headline
GHSA-8fp9-43pw-56vw: PandasAI vulnerable to arbitrary code execution
An issue in pandas-ai v.0.8.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak
function.
PandasAI vulnerable to arbitrary code execution
Critical severity GitHub Reviewed Published Aug 15, 2023 to the GitHub Advisory Database • Updated Aug 15, 2023
Related news
CVE-2023-39661: The fix of #issue399 (RCE from prompt) can be bypassed. · Issue #410 · gventuri/pandas-ai
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.