{"data":{"ecosystem":"pypi","name":"pandasai","url":"https://aisecwatch.com/packages/pypi/pandasai","latestVersion":"3.0.0","firstReleaseAt":"2023-04-24T11:33:15.472Z","repository":"https://github.com/sinaptik-ai/pandas-ai","llm":{"exposure":"none","depth":null,"integratedAt":null,"integratedVersion":null,"sdks":[],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"astor","versionSpec":"<0.9.0,>=0.8.1","scope":"runtime"},{"ecosystem":"pypi","name":"duckdb","versionSpec":"<2.0.0,>=1.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"jinja2","versionSpec":"<4.0.0,>=3.1.3","scope":"runtime"},{"ecosystem":"pypi","name":"matplotlib","versionSpec":"<3.8,>=3.7.1","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":"<2.0,>=1.17","scope":"runtime"},{"ecosystem":"pypi","name":"openpyxl","versionSpec":"<4.0.0,>=3.1.5","scope":"runtime"},{"ecosystem":"pypi","name":"pandas","versionSpec":"<3.0.0,>=2.0.3","scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":"<11.0.0,>=10.1.0","scope":"runtime"},{"ecosystem":"pypi","name":"pyarrow","versionSpec":"<19.0.0,>=14.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":"<3.0.0,>=2.6.4","scope":"runtime"},{"ecosystem":"pypi","name":"python-dotenv","versionSpec":"<2.0.0,>=1.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":"<7.0.0,>=6.0.2","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":"<3.0.0,>=2.31.0","scope":"runtime"},{"ecosystem":"pypi","name":"scipy","versionSpec":"==1.10.1","scope":"runtime"},{"ecosystem":"pypi","name":"seaborn","versionSpec":"<0.13.0,>=0.12.2","scope":"runtime"},{"ecosystem":"pypi","name":"sqlglot","versionSpec":"<26.0.0,>=25.0.3","scope":"runtime"}],"advisories":[{"id":"116efa2e-505f-4124-bd11-fb3494a477ab","url":"https://aisecwatch.com/issues/116efa2e-505f-4124-bd11-fb3494a477ab","cveId":"CVE-2024-12366","title":"CVE-2024-12366: PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that…","headline":"PandasAI prompt injection leads to arbitrary Python code execution","severity":"critical","publishedAt":"2025-02-11T13:15:29.193Z","affected":["pandasai@<= 2.4.2"],"epssScore":0.01214,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:54:29.117Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}