An issue in pandas-ai v.0.8.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.
_is_jailbreak
"https://github.com/pypa/advisory-database/blob/main/vulns/pandasai/PYSEC-2026-447.yaml"