SQL Injection Vulnerabilities in Llama Index by Run Llama
CVE-2025-1793

9.8CRITICAL

Key Information:

Vendor

Run-llama

Vendor
CVE Published:
5 June 2025

What is CVE-2025-1793?

Multiple vector store integrations in Llama Index version v0.12.21 are susceptible to SQL injection vulnerabilities. These security flaws may enable an attacker to manipulate database queries, thereby allowing unauthorized access to sensitive data. The impact of these vulnerabilities depends on how the Llama Index library is utilized within web applications, which highlights the need for developers to ensure secure database interaction practices.

Affected Version(s)

run-llama/llama_index < 0.12.28

References

CVSS V3.0

Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.
CVE-2025-1793 : SQL Injection Vulnerabilities in Llama Index by Run Llama