External risk intelligence

Vanna v2.0.2 Code Injection in get_plotly_figure

CVE advisorySeverity: CRITICAL (CVSS 9.8)

CVE-2026-51911

Vanna is a Python framework commonly used to build internet-facing data-querying web applications and APIs. Because this vulnerability exists in a core function responsible for rendering visualizations within such applications, these deployments are typically exposed to the internet to serve end users.

Code Injection

Halo Surface Signal: 4 out of 5 — likely to be public-facing.

External exposure likelihood

Horizon Alert

Summary of the vulnerability and why it matters

A code injection vulnerability has been identified in Vanna, a Python framework used for data querying applications. This flaw could allow an attacker to execute their own code or commands, depending on how the system is configured. The main concern at this stage is confirming if this specific technology is in use within our environment and understanding the potential exposure.

  • Code can be injected into applications.
  • Matters if applications use Vanna for data queries.
  • Confirm relevance and assess potential exposure.

Attack Path

How an attacker could exploit the issue

An attacker could gain control by sending specially crafted requests to a web application using Vanna, targeting the `get_plotly_figure` function. This function, when exposed, processes user input in a way that allows for the injection and execution of arbitrary code on the server, potentially leading to a complete compromise of the system.

  • No authentication required to trigger.
  • Code injection via `get_plotly_figure` function.
  • Risk of remote code execution.

Live Threat

Current exploitation, exposure, and threat context

A code injection vulnerability in Vanna's visualization rendering function could allow an attacker to execute arbitrary code or commands. This could occur when an attacker controls an entry point that triggers the vulnerable function, potentially impacting the integrity and availability of the system.

  • System data and service behavior.
  • Attacker-controlled input triggers code execution.
  • Arbitrary code execution and system compromise.

Operational Fix

Recommended remediation, mitigation, and detection steps

This vulnerability in the Vanna framework likely affects application owners responsible for data visualization tools and APIs that interact with Vanna. The initial step should be to identify all instances of Vanna, determine their exposure and criticality, and then confirm the accountable owner to plan remediation.

  • Application owners should prioritize investigation.
  • Verify Vanna's network exposure and criticality.
  • Plan risk-based remediation or vendor coordination.

Supplementary metadata

Validate whether this threat affects your internet-facing exposure.

Halo Threat Intelligence helps prioritize remediation with Halo Surface Signal and H/A/L/O context. Start exposure validation with a free external attack surface trial.

Frequently asked questions

What is Vanna and why is it used?

Vanna is a Python framework designed to help developers build applications that enable users to query databases using natural language. It is commonly integrated into web applications and APIs to generate data visualizations, making it easier for end users to interpret complex database insights without writing SQL themselves.

What does CWE-94 code injection mean for CVE-2026-51911?

CWE-94 refers to improper control of generation of code, often called code injection. In this CVE, the Vanna framework fails to properly sanitize input before passing it to the get_plotly_figure function. Because this function is intended to create visualizations, an attacker can supply malicious instructions that the server interprets as legitimate commands, allowing them to execute arbitrary code.

How does an attacker trigger this vulnerability?

An attacker triggers this by sending specially crafted input to an application that utilizes the vulnerable get_plotly_figure function. The vulnerability does not require authentication to trigger. It is important to note that simply having the Vanna library installed is not enough; the application must actively pass attacker-controlled or untrusted data into this specific visualization function for the code execution to occur.

Is my application at risk according to Halo Surface Signal?

Halo Surface Signal indicates that applications using this framework are often internet-facing, as they are typically deployed to serve data-querying interfaces to end users. If your Vanna-powered service is accessible from the internet, it is considered more likely to be reachable by an attacker. You should focus your investigation on any public-facing APIs or web portals that leverage Vanna to render these charts.

Do I need to take action if I use Vanna v2.0.2?

Yes, you should begin by creating an inventory of all applications within your environment that rely on Vanna. Once identified, verify which specific deployments utilize the vulnerable get_plotly_figure function and assess their network accessibility. Your primary goal is to confirm if the technology is present and determine its criticality so you can coordinate with your team on necessary updates or architectural changes.

References