Code execution in pandasai
Critical severity
GitHub Reviewed
Published
Jan 22, 2024
to the GitHub Advisory Database
•
Updated Feb 7, 2024
Description
Published by the National Vulnerability Database
Jan 22, 2024
Published to the GitHub Advisory Database
Jan 22, 2024
Reviewed
Jan 22, 2024
Last updated
Feb 7, 2024
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of this Python code. NOTE: the vendor previously attempted to restrict code execution in response to a separate issue, CVE-2023-39660.
References