CVE-2026-4998 | Sinaptik AI PandasAI up to 3.0.0 Chat Message code_executor.py CodeExecutor.execute code injection
A vulnerability was found in Sinaptik AI PandasAI up to 3.0.0. It has been declared as critical. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection.
The identification of this vulnerability is CVE-2026-4998. The attack may be launched remotely. Furthermore, there is an exploit available.
The vendor was contacted early about this disclosure but did not respond in any way.