
Nobody checked a box saying "execute attacker code". The boxes said "text to SQL" and "show me a chart". CVE-2024-5565, Vanna AI : the model writes your SQL, runs it, then writes the Python that draws the chart. And executes it. On by default. Three safe features
Post summary
The post discloses that CVE‑2024‑5565 in Vanna AI enables the model to generate and execute arbitrary SQL and Python code, with execution enabled by default.

