Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.
Metrics
Affected Vendors & Products
References
History
Wed, 30 Jul 2025 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Llamaindex
Llamaindex llamaindex |
|
CPEs | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
Vendors & Products |
Llamaindex
Llamaindex llamaindex |
Fri, 06 Jun 2025 19:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Thu, 05 Jun 2025 19:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Thu, 05 Jun 2025 05:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application. | |
Title | SQL Injection in run-llama/llama_index | |
Weaknesses | CWE-89 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-06-05T04:54:47.071Z
Updated: 2025-06-05T14:08:26.589Z
Reserved: 2025-02-28T18:09:06.434Z
Link: CVE-2025-1793

Updated: 2025-06-05T13:18:46.048Z

Status : Analyzed
Published: 2025-06-05T05:15:23.690
Modified: 2025-07-30T21:29:25.527
Link: CVE-2025-1793
