CVE-2026-4996 describes a high-severity SQL Injection vulnerability (CVSS 7.3) affecting Sinaptik AI PandasAI up to version 0.1.4, specifically within the pandasai-lancedb Extension's lancedb.py component. This flaw allows unauthenticated remote attackers to compromise data confidentiality, integrity, and availability with low attack complexity. Although not currently listed on the KEV catalog or Hot List, public exploit code is available, increasing the risk of future exploitation. The vendor was unresponsive to the disclosure, and community discussion is minimal, suggesting a potential lack of awareness despite the public exploit.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| Sinaptik AI | PandasAI | 0.1.0, 0.1.1, 0.1.2, 0.1.3, 0.1.4CNA affected |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.