PT-2023-27060 · Pandasai · Pandasai

Lyutoo

·

Published

2023-08-15

·

Updated

2023-08-22

·

CVE-2023-39661

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions pandas-ai versions 0.9.1 and earlier pandas-ai versions 0.8.1 and earlier
Description An issue in pandas-ai allows a remote attacker to execute arbitrary code via the is jailbreak function. This enables the attacker to perform malicious actions on the affected system.
Recommendations For versions 0.9.1 and earlier, update to a version later than 0.9.1 to resolve the issue. For versions 0.8.1 and earlier, update to a version later than 0.8.1 to resolve the issue. As a temporary workaround, consider disabling the is jailbreak function until a patch is available.

Exploit

Fix

Special Elements Injection

Code Injection

Weakness Enumeration

Related Identifiers

CVE-2023-39661
GHSA-8FP9-43PW-56VW

Affected Products

Pandasai