2.4.2
2 years ago
7 months ago
Known vulnerabilities in the pandasai package. This does not include vulnerabilities belonging to this package’s dependencies.
Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.
Fix for freeVulnerability | Vulnerable Version |
---|---|
pandasai is a Pandas AI is a Python library that integrates generative artificial intelligence capabilities into Pandas, making dataframes conversational. Affected versions of this package are vulnerable to Arbitrary Code Injection through the interactive prompt function. An attacker with access to the chat prompt can bypass PandasAI's restrictions to execute arbitrary code by injecting malicious inputs into the prompt, which are incorrectly processed as legitimate commands. How to fix Arbitrary Code Injection? Upgrade | [,2.4.2) |
pandasai is a Pandas AI is a Python library that integrates generative artificial intelligence capabilities into Pandas, making dataframes conversational. Affected versions of this package are vulnerable to Arbitrary Code Execution via the How to fix Arbitrary Code Execution? There is no fixed version for | [0,) |