CVE-2024-5565

8.1
HIGHCVSS v3.1 Base Score
15.18%
LOW RiskEPSS (97th percentile)

The Vanna library uses a prompt function to present the user with visualized results, it is possible to alter the prompt using prompt injection and run arbitrary Python code instead of the intended visualization code. Specifically - allowing external input to the library’s “ask” method with "visualize" set to True (default behavior) leads to remote code execution.

Published: 5/31/2024
Modified: 6/17/2026
Back to CVE Lookup

Vulnerability Summary

CVSS v3 Score

8.1HIGH

CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Score (Exploitation Probability)

15.18%LOW Exploitation Risk
97th percentile

This vulnerability has a 15.18% probability of being exploited in the next 30 days, ranking higher than 97% of all scored CVEs.

CWE Classification

Advertisement