Home ยป Database

AVID-2026-R1270

Description

Vulnerability CVE-2023-39660

Details

An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

Reason for inclusion in AVID: CVE-2023-39660 describes remote code execution in the pandasai library (versions before 0.8.0). This is a vulnerability in a software component (AI tooling/library) commonly used in AI pipelines, constituting a security risk in general-purpose AI systems. The issue is relevant to the AI software stack and has explicit references (NVD and GitHub discussions) providing evidence.

References

Affected or Relevant Artifacts

  • Developer: n/a
  • Deployer: n/a
  • Artifact Details:
TypeName
Systemn/a

Impact

AVID Taxonomy Categorization

  • Risk domains: Security
  • SEP subcategories: S0100: Software Vulnerability
  • Lifecycle stages: L06: Deployment

Other information

  • Report Type: Advisory
  • Credits:
  • Date Reported: 2023-08-21
  • Version: 0.3.3
  • AVID Entry