CVE-2026-51911: Code Injection
Published Oct 2, 2026
·Updated
vanna v2.0.2 contains a code injection vulnerability in VannaBase.getplotlyfigure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Affected Software
1 affected component
pypi/vanna=2.0.2
Event History
Oct 2, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·04:16 PM
Description