CVE-2025-1793Critical· 9.8▾ Midnightllama_index vulnerable to SQL Injection
▾ Midnight zone — Critical, or high with PoC / in-the-wild
impact 53.9 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 21.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
0.6%
0.6% → 0.7%
Last analysed / modified upstream
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.
llama-index < 0.12.28Upgrade to a patched release:
llama-index 0.12.28Connected by shared product, vendor, weakness, or advisory.
CVE-2025-7707High· 7.1llama-index has Insecure Temporary File
CVE-2024-4181High· 8.8RunGptLLM class in LlamaIndex has a command injection
CVE-2024-12911High· 7.1LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
CVE-2025-1752High· 7.5LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-6211Medium· 6.5LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
CVE-2025-1750Critical· 9.8An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnera…