Gabrieleventuri maintains PandasAI, a Python library designed to enable natural-language querying of data structures, with its disclosed vulnerabilities centered on code-injection and SQL-injection risks inherent to dynamic query generation and insufficient input validation in language-model-driven data access. The recurring weakness classes—code injection, generic injection, SQL injection, and missing authorization—reflect the structural hazard of translating user prompts into executable commands without rigorous sanitization. Current severity and exploitation activity are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Gabrieleventuri over time
Signals from CVEs in this vendor scope (4 CVEs).
4 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2024-23752CRITICAL GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCod | Jan 22, 2024 | 9.8 | 31 | NO | NO |
CVE-2023-39661CRITICAL An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function. | Aug 15, 2023 | 9.8 | 26 | NO | NO |
CVE-2023-39660CRITICAL An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function. | Aug 21, 2023 | 9.8 | 25 | NO | NO |
CVE-2026-30273HIGH pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component. | Apr 1, 2026 | 7.3 | 24 | NO | NO |
Signals from CVEs in this vendor scope (4 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Gabrieleventuri.
Media articles that mention a CVE ID that affects a product developed by Gabrieleventuri — matched by CVE ID, not by vendor name.