PT-2026-26886 · Unknown · Vanna-Ai Vanna

Goku

+1

·

Publicado

2026-03-21

·

Atualizado

2026-03-22

·

CVE-2026-4513

CVSS v2.0

6.5

Média

VetorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vanna-ai vanna versions up to 2.0.2
Description A SQL injection issue exists in vanna-ai vanna up to version 2.0.2. The issue is located in the ask function within the vannalegacybasebase.py file. A manipulation of input can lead to SQL injection, and the attack can be carried out remotely. The exploit is publicly available. The vendor was contacted but did not respond.
Recommendations Versions prior to 2.0.2 should be updated.

Exploit

Correção

Special Elements Injection

SQL injection

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-4513

Produtos afetados

Vanna-Ai Vanna