CVE-2026-4229General

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vector.py. This manipulation of the argument ID causes sql injection. The attack can be initiated remotely. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 1 signal
  • General: 1 classified signal
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-16); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-16: 1Mentions · 2026-04-13: 1Technical Details · 2026-03-16: 103-1604-13
Signal classification2 categories
General
150.0%
Disclosure
150.0%
Referenced assets1 URL
By indicator
Classification over time
DateTotalLabels
2026-03-161
General1
2026-04-131
Disclosure1
Full discourse2 posts
  • David@DavidMarquet19
    Disclosure

    📌 Top CVEs recientes (CVSS>=7.0): 1. 💉 CVE-2026-4235 (CVSS: 7.3) 2. 💉 CVE-2026-4232 (CVSS: 7.3) 3. 🕷️ CVE-2026-4231 (CVSS: 7.3) 4. 💉 CVE-2026-4229 (CVSS: 7.3) 5. 🧱 CVE-2026-4227 (CVSS: 8.8) #CyberSecurity #CVE #Infosec

    Post summary

    The post simply lists five newly disclosed high-severity CVEs with their CVSS scores, offering no additional technical, exploitation, or remediation details.

    0000051
    165 followersView on X
  • CVE@CVEnew
    General

    CVE-2026-4229 A flaw has been found in vanna-ai vanna up to 2.0.2. This impacts the function remove_training_data of the file src/vanna/legacy/google/bigquery_vector.py. This manipul… https://www.cve.org/CVERecord?id=CVE-2026-4229

    Post summary

    CVE‑2026‑4229 is reported as a flaw in vanna‑ai vanna up to version 2.0.2, impacting the `remove_training_data` function in a specific source file, with no additional details on exploits, patches, or active use.

    00000138
    56.7K followersView on X

Explore more