SQL Injection Vulnerabilities in Llama Index by Run Llama
CVE-2025-1793
9.8CRITICAL
What is CVE-2025-1793?
Multiple vector store integrations in Llama Index version v0.12.21 are susceptible to SQL injection vulnerabilities. These security flaws may enable an attacker to manipulate database queries, thereby allowing unauthorized access to sensitive data. The impact of these vulnerabilities depends on how the Llama Index library is utilized within web applications, which highlights the need for developers to ensure secure database interaction practices.
Affected Version(s)
run-llama/llama_index < 0.12.28