What happened
NVD published CVE-2026-51898 on 2026-10-02: pandas-ai 3.0.0 is vulnerable to code injection in CodeExecutor.execute. Unrated, awaiting vendor analysis; the code-exec gap is intrinsic to an LLM-codegen dataframe tool.
Why it matters
pandas-ai is an LLM-agent code-exec tool widely used in data/ML work; uncontained generated-code execution is the classic agent-RCE primitive — relevant to ML-infrastructure hygiene even without a confirmed public exploit (Tier C).
Attack vector
The CodeExecutor.execute path runs code generated for the LLM without adequate isolation; a manipulated prompt or dataset can steer execution to arbitrary commands on the host running the pandas-ai agent.
Affected systems
pandas-ai 3.0.0
Mitigation
Apply upstream fix once issued (sinaptik-ai/pandas-ai issue #1893); run pandas-ai only against trusted data/prompts or inside a sandbox.