SQL Injection Vulnerability in vanna-ai's Vanna Product
CVE-2026-4513
Key Information:
Badges
What is CVE-2026-4513?
A vulnerability has been identified in the Vanna product by vanna-ai, specifically in the 'ask' function located within the file 'base.py'. This issue allows for SQL injection attacks, which can be exploited remotely, enabling unauthorized access to the database and manipulation of data. The vulnerability affects all versions of Vanna up to 2.0.2. Exploitation of this weakness is now publicly documented, highlighting the urgent need for users to implement security measures and update their systems accordingly. The vendor's response to this disclosure remains unaddressed, raising concerns about the overall security posture of the affected product.
Affected Version(s)
vanna 2.0.0
vanna 2.0.1
vanna 2.0.2
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved
