CVE-2026-4511

MEDIUM

vanna-ai vanna legacy exec injection

Title source: cna

Description

A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. Affected is the function exec of the file /src/vanna/legacy. Such manipulation leads to injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Scores

CVSS v3 6.3
EPSS 0.0005
EPSS Percentile 16.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:L/A:L

Details

CWE
CWE-707 CWE-74
Status published
Products (3)
vanna-ai/vanna 2.0.0
vanna-ai/vanna 2.0.1
vanna-ai/vanna 2.0.2
Published Mar 21, 2026
Tracked Since Mar 21, 2026