---
id: CVE-2024-46488
aliases:
  - GHSA-vrcx-gx3g-j3h8
  - PYSEC-2026-1938
title: Heap-based Buffer Overflow in sqlite-vec
summary: Heap-based Buffer Overflow in sqlite-vec
severity: critical
cvss: 9.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H'
vendor: sqlite-vec
product: sqlite-vec
ecosystem: pip
affected:
  - sqlite-vec < 0.1.3
  - sqlite-vec < 0.1.3
  - sqlite-vec < 0.1.3
  - sqlite-vec < 0.1.3
patched:
  - sqlite-vec 0.1.3
  - sqlite-vec 0.1.3
  - sqlite-vec 0.1.3
  - sqlite-vec 0.1.3
published: '2024-09-25'
updated: '2026-07-07'
source: OSV
sourceUrl: 'https://osv.dev/vulnerability/GHSA-vrcx-gx3g-j3h8'
references:
  - url: 'https://nvd.nist.gov/vuln/detail/CVE-2024-46488'
  - url: >-
      https://github.com/VulnSphere/LLMVulnSphere/blob/main/VectorDB/sqlite-vec/OOBR_2.md
  - url: 'https://github.com/advisories/GHSA-vrcx-gx3g-j3h8'
  - url: 'https://github.com/asg017/sqlite-vec'
  - url: 'https://github.com/asg017/sqlite-vec/releases/tag/v0.1.3'
  - url: >-
      https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sqlite-vec/CVE-2024-46488.yml
tags:
  - osv
  - pip
epss: 0.00438
epssPercentile: 0.35362
ingestedAt: '2026-07-08T18:25:53.379Z'
---

## Overview

sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.

## Affected packages

- `sqlite-vec < 0.1.3`
- `sqlite-vec < 0.1.3`
- `sqlite-vec < 0.1.3`
- `sqlite-vec < 0.1.3`

## Remediation

Upgrade to a patched release:

- `sqlite-vec 0.1.3`
- `sqlite-vec 0.1.3`
- `sqlite-vec 0.1.3`
- `sqlite-vec 0.1.3`
