PT-2026-26886 · Unknown · Vanna-Ai Vanna

Goku

+1

·

Published

2026-03-21

·

Updated

2026-03-22

·

CVE-2026-4513

CVSS v2.0

6.5

Medium

VectorAV:N/AC:L/Au:S/C:P/I:P/A:P
Name of the Vulnerable Software and Affected Versions vanna-ai vanna versions up to 2.0.2
Description A SQL injection issue exists in vanna-ai vanna up to version 2.0.2. The issue is located in the ask function within the vannalegacybasebase.py file. A manipulation of input can lead to SQL injection, and the attack can be carried out remotely. The exploit is publicly available. The vendor was contacted but did not respond.
Recommendations Versions prior to 2.0.2 should be updated.

Exploit

Fix

Special Elements Injection

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2026-4513

Affected Products

Vanna-Ai Vanna