PT-2026-28716 · Sinaptik Ai · Pandasai
Eric-B
+1
·
Published
2026-03-28
·
Updated
2026-03-29
·
CVE-2026-4998
CVSS v2.0
7.5
High
| Vector | AV:N/AC:L/Au:N/C:P/I:P/A:P |
Name of the Vulnerable Software and Affected Versions
Sinaptik AI PandasAI versions up to 3.0.0
Description
A code injection weakness exists in the Chat Message Handler component, specifically within the
CodeExecutor.execute function of the pandasai/core/code execution/code executor.py file. This allows for remote code execution through manipulation. The exploit is publicly available. The vendor was notified but did not respond.Recommendations
Versions prior to 3.0.0 should be used. As a temporary workaround, consider restricting access to the
CodeExecutor.execute function until a patch is available.Exploit
Fix
Special Elements Injection
Code Injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Pandasai