


Perceptive Security
SOC/SIEM Consultancy

A security vulnerability has been detected in vanna-ai vanna up to 2.0.2. The affected element is an unknown function of the component Legacy Flask API. The man…
Published:
24 April 2026 at 22:00:00
Alert date:
25 April 2026 at 12:00:43
Source:
nvd.nist.gov
Web Technologies
A security vulnerability has been detected in vanna-ai vanna up to version 2.0.2. The vulnerability affects an unknown function of the Legacy Flask API component and leads to improper authorization. The attack can be initiated remotely and the exploit has been publicly disclosed. The vendor was contacted about the disclosure but did not respond.
Technical details
Mitigation steps:
Affected products:
vanna-ai vanna
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-6977
https://github.com/yidaozhongqing/York/issues/2
https://vuldb.com/submit/795331
https://vuldb.com/vuln/359520
https://vuldb.com/vuln/359520/cti
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
