Skip to content
LlamaIndexGHSA-2jxw-4hm4-6w87

SQL injection in llama-index

Critical9.8CVE-2024-23751 · Published Jan 22, 2024 · updated Feb 16, 2024

LlamaIndex (aka llama_index) through 0.9.35 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be able to delete this year's student records via "Drop the Students table" within English language input.

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index
PyPI
<= 0.9.35No fix yet
Details and references
CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-89
Also known as
CVE-2024-23751, PYSEC-2024-12

More LlamaIndex advisories

All LlamaIndex
Advisory
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
High7.5Mar 20, 2025
LlamaIndex includes an exec call for `import {cls_name}`
Critical9.8Aug 22, 2024
RunGptLLM class in LlamaIndex has a command injection
High8.8May 16, 2024
llama-index-core Command Injection vulnerability
Critical9.8Apr 16, 2024
llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
Critical9.8Apr 10, 2024
llama-index vulnerable to arbitrary code execution
Critical9.8Aug 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.