/
DirectorySecurity AdvisoriesPricing
Sign in
Security Advisories

CVE-2025-24793

Published

Last updated

NVD

https://nvd.nist.gov/vuln/detail/CVE-2025-24793

Severity

7.0

High

CVSS V3

Summary

Snowflake Connector for Python has an SQL Injection in write_pandas

Description

The Snowflake Connector for Python provides an interface for developing Python applications that can connect to Snowflake and perform all standard operations. Snowflake discovered and remediated a vulnerability in the Snowflake Connector for Python. A function from the snowflake.connector.pandas_tools module is vulnerable to SQL injection. This vulnerability affects versions 2.2.5 through 3.13.0. Snowflake fixed the issue in version 3.13.1.

References

Affected packages


The trusted source for open source

Talk to an expert
© 2025 Chainguard. All Rights Reserved.
PrivacyTerms

Product

Chainguard ContainersChainguard LibrariesChainguard VMsIntegrationsPricing