All 4 CVE vulnerabilities found in PandasAI, with AI-generated Chinese analysis, references, and POCs.
Vendor: Sinaptik AI
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-4998 | Sinaptik AI PandasAI Chat Message code_executor.py CodeExecutor.execute code injection CWE-94 | 7.3 | High | 2026-03-28 |
| CVE-2026-4997 | Sinaptik AI PandasAI sql_sanitizer.py is_sql_query_safe path traversal CWE-22 | 5.3 | Medium | 2026-03-28 |
| CVE-2026-4996 | Sinaptik AI PandasAI pandasai-lancedb Extension lancedb.py get_relevant_docs_by_id sql injection CWE-89 | 7.3 | High | 2026-03-28 |
| CVE-2024-12366 | CVE-2024-12366 | 8.8 | - | 2025-02-11 |
All 4 known CVE vulnerabilities affecting PandasAI with full Chinese analysis, references, and POCs where available.