CVE-2024-12366

PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.
Configurations

No configuration.

History

No history.

Information

Published : 2025-02-11 13:15

Updated : 2026-06-17 06:59


NVD link : CVE-2024-12366

Mitre link : CVE-2024-12366

CVE.ORG link : CVE-2024-12366


JSON object : View

Products Affected

No product.

CWE

No CWE.