logo

Prompt Injection Flaw in Vanna AI Exposes Databases to RCE Attacks

ID: 50048af5-a983-5df5-8ecd-c4f403982418

STIX ID: report--50048af5-a983-5df5-8ecd-c4f403982418

Feed Name: The Hacker News

Threat Score
70/100

Date Published: 2024-06-27

Date Updated: 2026-05-11

Author: [email protected] (The Hacker News)

...
...

Cybersecurity researchers disclosed CVE-2024-5565, a high-severity prompt-injection vulnerability in the Vanna.AI Python library that can lead to remote code execution when the 'ask' function's visualization (Plotly) integration executes LLM-generated code; JFrog and independent researchers detailed the technique and Vanna published hardening guidance recommending sandboxing and stricter handling of externally supplied prompts.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.