CVE-2026-4996Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of the component pandasai-lancedb Extension. Such manipulation leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-89

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-03-28); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-03-28: 2Mentions · 2026-03-29: 1Technical Details · 2026-03-28: 203-2803-29
Signal classification1 categories
Disclosure
3100.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-03-282
Disclosure2
2026-03-291
Disclosure1
Full discourse3 posts
  • CVEarity@CVEarity
    Disclosure

    ⚡ New CVE Alert: CVE-2026-4996 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4996 #CVE-2026-4996 #CVE #High #CyberSecurity #InfoSec https://t.co/YpYGMb8UbJ

    Post summary

    The tweet announces a new vulnerability CVE-2026-4996, noting its severity (7.3) and high risk, and provides a link to the NVD entry.

    0000031
    123 followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-4996 A vulnerability was identified in Sinaptik AI PandasAI up to 0.1.4. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answe… https://www.cve.org/CVERecord?id=CVE-2026-4996

    Post summary

    CVE-2026-4996 is disclosed as affecting Sinaptik AI PandasAI’s delete_question_and_answers/delete_docs/update_question_answe functions up to version 0.1.4, with a reference to the CVE record.

    00000182
    56.9K followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4996 - Sinaptik AI PandasAI pandasai-lancedb Extension http://lancedb.py get_relevant_docs_by_id sql injection Intel Report: https://ift.tt/sTLu2b5

    Post summary

    The alert announces CVE-2026-4996 affecting the Sinaptik AI PandasAI pandasai-lancedb Extension via a SQL injection vector, but provides no PoC, exploit code, patch, or evidence of active exploitation.

    0000020
    283 followersView on X

Explore more