vanna-ai vendor intelligence
vanna-ai Known Exploited Vulnerabilities
Track evidence-backed exploitation affecting vanna-ai products, including the gap beyond CISA KEV, confidence assessments, sensor observations, and practical response context.
- Total KEVs
- 1
- Known exploited vulnerabilities affecting vanna-ai products
- In CISA KEV
- 0
- Records also listed in the official catalog
- Beyond CISA KEV
- 1
- Additional exploited CVEs absent from CISA KEV
- Sensor Observed
- 0
- vanna-ai KEVs with sensor-observed exploitation activity
The catalog gap matters for vanna-ai exposure
One of the one exploited vanna-ai CVEs tracked here are not in CISA KEV. Teams relying on the official catalog alone would miss 100% of this vendor portfolio.
- 0%
- Covered by CISA
- 100%
- Beyond CISA
- 1
- Product families
Attested vanna-ai CVEs
Search the exploited-vulnerability portfolio, then narrow it to official CISA coverage or the additional records KEV Intelligence tracks beyond the catalog.
How exploitation is verified| CVE / description | Product | Confidence | CISA KEV | Added |
|---|---|---|---|---|
|
CVE-2024-5827
Arbitrary File Write by Prompt Injection via DuckDB SQL in vanna-ai/vanna |
vanna-ai/vanna | High | Beyond CISA | 26 Jun 2025 |
No vanna-ai CVEs match this search or filter.
Showing 1 of 1 vanna-ai known exploited vulnerabilities.
Recurring weakness patterns
Neutralization account for one mapped occurrence across this vanna-ai KEV portfolio.
Early warning alerts
Get alerts on high-impact exploitation
Receive curator-selected alerts when exploitation activity warrants attention. Each alert includes the evidence and context needed to decide what requires attention now.