VDB
CVE-2025-24793
CVE-2025-24793
PUBLISHED
CVSS 7 HIGH
snowflake-connector-python vulnerable to SQL Injection in write_pandas
EPSS 0.19% · 40.5th percentile
Risk Scores
CVSS v3.1
7
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.19%
40.5th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| snowflakedb | snowflake-connector-python | >= 2.2.5, < 3.13.1 |
| snowflake | snowflake_connector | 2.2.5 |
| PyPI | snowflake-connector-python | 2.2.5 |
Timeline
- Jan 21, 1970 Security Advisory
- Jan 29, 2025 CVE Published
- Jan 29, 2025 Coalition ESS Score
- Jan 29, 2025 PoC Published
- Jan 29, 2025 PoC Published
- Jan 30, 2025 EPSS Score
- Feb 14, 2025 EPSS Score
- Mar 1, 2025 EPSS Score
- Mar 16, 2025 EPSS Score
- Mar 31, 2025 EPSS Score
- Apr 15, 2025 EPSS Score
- Apr 30, 2025 EPSS Score
References
- https://github.com/snowflakedb/snowflake-connector-python/releases/tag/v3.13.1 url
- https://github.com/snowflakedb/snowflake-connector-python/security/advisories/GHSA-2vpq-fh52-j3wv url
- https://github.com/snowflakedb/snowflake-connector-python/commit/f3f9b666518d29c31a49384bbaa9a65889e72056 url
- https://nvd.nist.gov/vuln/detail/CVE-2025-24793 advisory
- https://github.com/pypa/advisory-database/tree/main/vulns/snowflake-connector-python/PYSEC-2025-26.yaml url
- https://github.com/snowflakedb/snowflake-connector-python package