PyPI: pandasai

CVE-2023-39660

Safety vulnerability ID: SFTY-20230821-93947

Safety legacy ID: pyup.io-65037

An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

Created at: Nov 6, 2025Updated at: Nov 6, 2025

Overview

pandasai vulnerable to prompt injection

Advisory

An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

Affected Package

Affecting pandasai package, versions
>=0,<0.8.1

Also affects

---

How to Fix

Upgrade
pandasai
to
0.8.1
or higher.

Mitigation and Workarounds

---

Vulnerable Functions

Functions linked to known vulnerabilities.

Vulnerable function data is available for Enterprise customers

Book a call with us to see Safety in action.

Safety

Verified by Safety

Our Cybersecurity Intelligence Team reviewed this vulnerability. We combine public data with our own research to find issues not yet reported to public sources.

Learn more