QID 997010
Date Published: 2024-01-31
QID 997010: Python (Pip) Security Update for pandasai (GHSA-5g73-69p4-7gvx)
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.
Successful exploitation of this vulnerability could lead to a security breach or could affect integrity, availability, and confidentiality.
Solution
Refer to Github security advisory GHSA-5g73-69p4-7gvx for updates and patch information.
Vendor References
- GHSA-5g73-69p4-7gvx -
github.com/advisories/GHSA-5g73-69p4-7gvx
CVEs related to QID 997010
Software Advisories
| Advisory ID | Software | Component | Link |
|---|