logo

Vanna AI Vulnerability Exposes SQL Databases to Remote Code Execution

ID: 23e5c36a-cf18-59c1-a7c7-cffdfad79833

STIX ID: report--23e5c36a-cf18-59c1-a7c7-cffdfad79833

Feed Name: The Cyber Express

Threat Score
72/100

Date Published: 2024-06-28

Date Updated: 2026-04-23

Author: Ashish Khaitan

...
...

A critical prompt-injection vulnerability (CVE-2024-5565, CVSS 8.1) was discovered in the Vanna.AI Python library’s "ask" function that can allow attackers to craft malicious prompts to manipulate LLM-generated SQL and achieve remote code execution and unauthorized database operations; the issue was reported by JFrog and Tong Liu and Vanna.AI has released mitigations and guidance to address the flaw.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.