What happened
NVD published (2026-10-02) a code-injection finding in pandas-ai 3.0.0's CodeExecutor.execute. The library's core loop executes code to answer natural-language data questions; the injection permits arbitrary instructions to run in that execution context.
Why it matters
pandas-ai is a mainstream GenAI-to-data bridge: LLM-generated pandas code already executes in users' pipelines, so a code-injection flaw in that executor converts prompt-facing applications into arbitrary-code-execution vectors against data science/analytics infrastructure.
Attack vector
Code injection in the pandas-ai CodeExecutor.execute path lets an attacker inject arbitrary instructions/code into what is otherwise LLM-generated execution, achieving code execution in the process/container hosting the data application.
Affected systems
sinaptik-ai pandas-ai 3.0.0 (CodeExecutor.execute)
Mitigation
Upgrade/apply fix per tracking issue (https://github.com/sinaptik-ai/pandas-ai/issues/1893); run pandas-ai in a sandboxed execution environment and treat its code-executor as an untrusted-code boundary.