CVE-2026-4513 identifies a SQL Injection vulnerability (CWE-89) in the `ask` function of vanna-ai vanna versions up to 2.0.2. This medium-severity issue (CVSS 6.3) allows a remote, low-privileged attacker to achieve SQL injection, potentially impacting confidentiality, integrity, and availability. While public exploit code exists, there is no indication of active exploitation, and community discussion or media coverage is currently absent. The vendor did not respond to the initial disclosure of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Vanna-Ai | Vanna | 2.0.0, 2.0.1, 2.0.2CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.