CVE-2026-4998Disclosure

LOWCVSS 5.5 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

A weakness has been identified in Sinaptik AI PandasAI up to 3.0.0. This vulnerability affects the function CodeExecutor.execute of the file pandasai/core/code_execution/code_executor.py of the component Chat Message Handler. Executing a manipulation can lead to code injection. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74CWE-94

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • Disclosure: 1 classified signal
  • General: 1 classified signal
  • Peaked 1d ago at 1 mentions (2026-03-28); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-03-28: 1Mentions · 2026-03-29: 1Technical Details · 2026-03-28: 1Technical Details · 2026-03-29: 103-2803-29
Signal classification2 categories
Disclosure
150.0%
General
150.0%
Referenced assets2 URLs
By indicator
Classification over time
DateTotalLabels
2026-03-281
Disclosure1
2026-03-291
General1
Full discourse2 posts
  • CVEarity@CVEarity
    General

    ⚡ New CVE Alert: CVE-2026-4998 📊 Severity: 7.3 🚨 Risk Level: High 🧩 Affects: Multiple / Unspecified Products Reference: https://nvd.nist.gov/vuln/detail/CVE-2026-4998 #CVE-2026-4998 #CVE #High #CyberSecurity #InfoSec https://t.co/RIpbukHtzR

    Post summary

    A tweet merely announces CVE-2026-4998, citing a 7.3 CVSS score and high risk, but it offers no further technical, exploit, or patch information.

    0000031
    123 followersView on X
  • CyberDudeBivash® | Global Cybersecurity Company@cyberbivash
    Disclosure

    🚨 CYBERDUDEBIVASH SENTINEL APEX ALERT 🚨 Threat: CVE-2026-4998 - Sinaptik AI PandasAI Chat Message code_executor.py CodeExecutor.execute code injection Intel Report: https://ift.tt/nDYG8q4

    Post summary

    The alert highlights CVE‑2026‑4998 as a code injection flaw in Sinaptik AI's PandasAI Chat Message component, offering limited technical detail but lacking evidence of exploitation, patches, or PoC.

    0000023
    283 followersView on X

Explore more