PT-2026-25639 · Vanna-Ai · Vanna
Eric-Y
+1
·
Published
2026-03-16
·
Updated
2026-03-16
·
CVE-2026-4229
CVSS v3.1
7.3
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L |
A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove training data of the file src/vanna/legacy/google/bigquery vector.py. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.
Exploit
Fix
Special Elements Injection
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Vanna