CVE-2024-23752

GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.
References
Link Resource
https://github.com/gventuri/pandas-ai/issues/868 Exploit Mailing List Vendor Advisory
https://github.com/gventuri/pandas-ai/issues/868 Exploit Mailing List Vendor Advisory
Configurations

Configuration 1 (hide)

cpe:2.3:a:gabrieleventuri:pandasai:*:*:*:*:*:python:*:*

History

21 Nov 2024, 08:58

Type Values Removed Values Added
References () https://github.com/gventuri/pandas-ai/issues/868 - Exploit, Mailing List, Vendor Advisory () https://github.com/gventuri/pandas-ai/issues/868 - Exploit, Mailing List, Vendor Advisory

29 Jan 2024, 19:27

Type Values Removed Values Added
First Time Gabrieleventuri
Gabrieleventuri pandasai
References () https://github.com/gventuri/pandas-ai/issues/868 - () https://github.com/gventuri/pandas-ai/issues/868 - Exploit, Mailing List, Vendor Advisory
CWE CWE-862
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 9.8
CPE cpe:2.3:a:gabrieleventuri:pandasai:*:*:*:*:*:python:*:*

22 Jan 2024, 01:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-01-22 01:15

Updated : 2024-11-21 08:58


NVD link : CVE-2024-23752

Mitre link : CVE-2024-23752

CVE.ORG link : CVE-2024-23752


JSON object : View

Products Affected

gabrieleventuri

  • pandasai
CWE
CWE-862

Missing Authorization