CVE-2026-4513General

LOWCVSS 2.1 · LOW

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\base.py. Performing a manipulation results in sql injection. The attack is possible to be carried out remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Disclosure: 1 classified signal
  • Peaked 1d ago at 2 mentions (2026-03-21); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-21: 2Mentions · 2026-03-22: 1Technical Details · 2026-03-21: 203-2103-22
Signal classification2 categories
General
266.7%
Disclosure
133.3%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-212
Disclosure1General1
2026-03-221
General1
Full discourse3 posts
  • CVE@CVEnew
    General

    CVE-2026-4513 A vulnerability was detected in vanna-ai vanna up to 2.0.2. Affected by this vulnerability is the function ask of the file vanna\legacy\base\http://base.py. Performing a manip… https://www.cve.org/CVERecord?id=CVE-2026-4513

    Post summary

    The post merely announces a CVE affecting vanna‑ai up to version 2.0.2 and identifies the vulnerable function, with no accompanying PoC, exploit details, patch information, or evidence of active exploitation.

    0000079
    56.8K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    General

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4513 - vanna-ai vanna http://base.py ask sql injection Intel Report: https://ift.tt/dCsSkDP

    Post summary

    The tweet reports CVE‑2026‑4513 as a SQL injection vulnerability in vanna‑ai, provides an intel report link, but offers no proof of concept, exploit, active usage, or patch information.

    0000025
    334 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-4513 SQL Injection Vulnerability in Vanna AI Up to 2.0.2 via Remote Attack https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-4513

    Post summary

    The post announces CVE-2026-4513 as a SQL injection flaw affecting Vanna AI up to version 2.0.2, without mentioning PoC, exploitation activity, or patches.

    0000036
    4.0K followersView on X

Explore more