GHSA-6mj8-jmp2-g8q7

Suggest an improvement
Source
https://github.com/advisories/GHSA-6mj8-jmp2-g8q7
Import Source
https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6mj8-jmp2-g8q7/GHSA-6mj8-jmp2-g8q7.json
JSON Data
https://api.osv.dev/v1/vulns/GHSA-6mj8-jmp2-g8q7
Aliases
  • CVE-2026-4229
Published
2026-03-16T15:30:46Z
Modified
2026-03-17T20:47:43.510228Z
Severity
  • 7.3 (High) CVSS_V3 - CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L CVSS Calculator
  • 5.5 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Vanna has a SQL injection in the remove_training_data function
Details

A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function removetrainingdata of the file src/vanna/legacy/google/bigquery_vector.py. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Database specific
{
    "github_reviewed": true,
    "github_reviewed_at": "2026-03-17T20:32:43Z",
    "severity": "MODERATE",
    "nvd_published_at": "2026-03-16T14:20:16Z",
    "cwe_ids": [
        "CWE-74",
        "CWE-89"
    ]
}
References

Affected packages

PyPI / vanna

Package

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0Unknown introduced version / All previous versions are affected
Last affected
2.0.2

Affected versions

0.*
0.0.1
0.0.2
0.0.3
0.0.4
0.0.5
0.0.6
0.0.7
0.0.8
0.0.9
0.0.10
0.0.11
0.0.12
0.0.13
0.0.14
0.0.15
0.0.16
0.0.17
0.0.18
0.0.19
0.0.20
0.0.21
0.0.22
0.0.23
0.0.24
0.0.25
0.0.26
0.0.27
0.0.28
0.0.29
0.0.30
0.0.31
0.0.32
0.0.33
0.0.34
0.0.35
0.0.36
0.0.37
0.0.38
0.1.0
0.1.1
0.2.0
0.2.1
0.3.0
0.3.1
0.3.2
0.3.3
0.3.4
0.4.0
0.4.1
0.4.2
0.4.3
0.5.0
0.5.1
0.5.2
0.5.3
0.5.4
0.5.5
0.6.0
0.6.1
0.6.2
0.6.3
0.6.4
0.6.5
0.6.6
0.7.0
0.7.1
0.7.2
0.7.3
0.7.4
0.7.5
0.7.6
0.7.7
0.7.8
0.7.9
2.*
2.0.0rc1
2.0.0
2.0.1
2.0.2

Database specific

source
"https://github.com/github/advisory-database/blob/main/advisories/github-reviewed/2026/03/GHSA-6mj8-jmp2-g8q7/GHSA-6mj8-jmp2-g8q7.json"