PT-2024-36568 · Unknown · Vanna Library

Natan Nehorai

·

Published

2024-05-31

·

Updated

2024-11-25

·

CVE-2024-5565

CVSS v4.0

9.2

Critical

VectorAV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vanna library (affected versions not specified)
Description The Vanna library is affected by a remote code execution issue due to prompt injection. This allows an attacker to alter the prompt function used for visualized results and run arbitrary Python code. The issue arises when external input is allowed to the library's ask method with visualize set to True, which is the default behavior. This vulnerability has been reportedly exploited in the wild.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Code Injection

Command Injection

Weakness Enumeration

Related Identifiers

CVE-2024-5565
GHSA-7735-W2JP-GVG6

Affected Products

Vanna Library