pandas-ai v3.0.0 was discovered to contain a SQL injection vulnerability via the pandasai.agent.base._execute_sql_query component.
| Vendor | Product | Versions |
|---|---|---|
| Sinaptik AI | pandas-ai | — |
Updated vendor to Sinaptik AI, product to pandas-ai, severity to CRITICAL, and marked as actively exploited.
Initial creation