SQL Injection Vulnerabilities in Llama Index by Run Llama
CVE-2025-1793
9.8CRITICAL
What is CVE-2025-1793?
Multiple vector store integrations in Llama Index version v0.12.21 are susceptible to SQL injection vulnerabilities. These security flaws may enable an attacker to manipulate database queries, thereby allowing unauthorized access to sensitive data. The impact of these vulnerabilities depends on how the Llama Index library is utilized within web applications, which highlights the need for developers to ensure secure database interaction practices.
Affected Version(s)
run-llama/llama_index < 0.12.28
References
CVSS V3.0
Score:
9.8
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
