CVE-2026-51911: n/a
vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
AI Analysis
Technical Summary
CVE-2026-51911 is a code injection vulnerability found in Vanna v2.0.2 within the method VannaBase.get_plotly_figure located in src/vanna/legacy/base/base.py. An attacker can exploit this vulnerability by triggering an exposed entry point to execute attacker-controlled code or commands. The affected versions are all releases before 2.0.3.
Potential Impact
Successful exploitation could lead to arbitrary code or command execution on the affected system, potentially compromising system integrity and confidentiality. No active exploitation has been reported so far.
Mitigation Recommendations
Upgrade to Vanna version 2.0.3 or later, where this vulnerability is fixed. Since the affectedVersions are specified as versions prior to 2.0.3, applying this update will remediate the issue.
CVE-2026-51911: n/a
Description
vanna v2.0.2 contains a code injection vulnerability in VannaBase.get_plotly_figure (src/vanna/legacy/base/base.py). Depending on the exposed entry, an attacker can trigger attacker-controlled code or command execution.
Affected software
Run on your own infrastructure? Check whether these packages are installed with threat-finder — our free open-source scanner.
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
CVE-2026-51911 is a code injection vulnerability found in Vanna v2.0.2 within the method VannaBase.get_plotly_figure located in src/vanna/legacy/base/base.py. An attacker can exploit this vulnerability by triggering an exposed entry point to execute attacker-controlled code or commands. The affected versions are all releases before 2.0.3.
Potential Impact
Successful exploitation could lead to arbitrary code or command execution on the affected system, potentially compromising system integrity and confidentiality. No active exploitation has been reported so far.
Mitigation Recommendations
Upgrade to Vanna version 2.0.3 or later, where this vulnerability is fixed. Since the affectedVersions are specified as versions prior to 2.0.3, applying this update will remediate the issue.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- mitre
- Date Reserved
- 2026-06-08T00:00:00.000Z
- State
- PUBLISHED
Threat ID: 6abfd567a43b0b3b89d3b446
Added to database: 10/02/2026, 16:01:43 UTC
Last enriched: 10/02/2026, 16:16:19 UTC
Last updated: 10/03/2026, 03:04:29 UTC
Views: 9
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.