CVE-2026-51911
Received Received - Intake

Code Injection in Vanna v2.0.2

Vulnerability report for CVE-2026-51911, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-02

Last updated on: 2026-10-02

Assigner: MITRE

Description

vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-02
Last Modified
2026-10-02
Generated
2026-10-02
AI Q&A
2026-10-02
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
vanna vanna 2.0.2

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-UNKNOWN

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-51911 is a code injection vulnerability in the Vanna library version 2.0.2. It exists in the VannaBase.get_plotly_figure function located in src/vanna/legacy/base/base.py. An attacker can exploit this by sending malicious payloads through the Vanna API endpoint, such as /api/v0/generate_plotly_figure, to execute arbitrary code or commands. The vulnerability is classified under CWE-94 (Code Injection).

Detection Guidance

To detect this vulnerability, monitor network traffic for suspicious requests to the Vanna API endpoint, particularly /api/v0/generate_plotly_figure. Check logs for unusual payloads in the prompt or question fields that may indicate code injection attempts. Inspect the VannaBase.get_plotly_figure function in src/vanna/legacy/base/base.py for unauthorized code execution.

Impact Analysis

If you are using Vanna v2.0.2, an attacker could exploit this vulnerability to run malicious code or commands on your system. This could lead to unauthorized access, data breaches, or system compromise. The impact depends on the privileges of the Vanna service and the attacker's goals.

Compliance Impact

This vulnerability could lead to unauthorized data access or exfiltration, violating GDPR's data protection requirements and HIPAA's safeguards for protected health information. Compliance may be compromised if sensitive data is exposed or altered due to the code injection.

Mitigation Strategies

Immediately upgrade to a patched version of Vanna if available. If using v2.0.2, disable the affected API endpoint /api/v0/generate_plotly_figure. Implement input validation to sanitize prompt or question fields. Restrict network access to the Vanna service and monitor for anomalous activity.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-51911. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart