Skip to content
LlamaIndexGHSA-v3c8-3pr6-gr7p

llama_index vulnerable to SQL Injection

Critical9.8CVE-2025-1793 · Published Jun 5, 2025 · updated Sep 10, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index
PyPI
< 0.12.280.12.28
Details and references

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-89
Also known as
CVE-2025-1793, PYSEC-2026-394

More LlamaIndex advisories

All LlamaIndex
DateAdvisory
Jun 22025An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code
CVE-2025-1750Critical9.8fixed in 0.12.21
May 282025LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files` argument, which is directly passed into `os.system`. An attacker who controls the content of this argument can inject and execute arbitrary shell comm
CVE-2025-1753High7.8no fix yet
May 102025LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-1752High7.5fixed in 0.12.21
Jul 72025LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-3108Medium5.0fixed in 0.12.41
Jul 72025A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other,
CVE-2025-3044Medium5.3fixed in 0.12.28
Jul 72025A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within th
CVE-2025-3046High7.5fixed in 0.12.28

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.