CVE-2025-24793

CVSS 3.1 Score 7 of 10 (high)

Details

Published Jan 29, 2025
CWE ID 89

Summary

CVE-2025-24793: A vulnerability was discovered in the Snowflake Connector for Python, specifically in the snowflake.connector.pandas_tools module. This issue allows SQL injection attacks due to insufficient input validation. Versions 2.2.5 through 3.13.0 are affected, and Snowflake addressed the vulnerability in version 3.13.1. Users of the Snowflake Connector for Python are encouraged to update to the latest version to mitigate this risk.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share