CVE-2026-4996 | Sinaptik AI PandasAI up to 0.1.4 pandasai-lancedb Extension lancedb.py sql injection
A vulnerability was found in Sinaptik AI PandasAI up to 0.1.4 and classified as critical. Affected by this issue is the function delete_question_and_answers/delete_docs/update_question_answer/update_docs/get_relevant_question_answers_by_id/get_relevant_docs_by_id of the file extensions/ee/vectorstores/lancedb/pandasai_lancedb/lancedb.py of the component pandasai-lancedb Extension. Such manipulation leads to sql injection.
This vulnerability is uniquely identified as CVE-2026-4996. The attack can be launched remotely. Moreover, an exploit is present.
The vendor was contacted early about this disclosure but did not respond in any way.