Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks
ID: 50048af5-a983-5df5-8ecd-c4f403982418
STIX ID: report--50048af5-a983-5df5-8ecd-c4f403982418
Feed Name: The Hacker News
Threat Score
Cybersecurity researchers disclosed CVE-2024-5565, a high-severity prompt-injection vulnerability in the Vanna.AI Python library that can lead to remote code execution when the 'ask' function's visualization (Plotly) integration executes LLM-generated code; JFrog and independent researchers detailed the technique and Vanna published hardening guidance recommending sandboxing and stricter handling of externally supplied prompts.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
