LlamaIndexPYSEC-2025-245
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code
Critical9.8CVE-2025-1750 · Published Jun 2, 2025 · updated Jul 13, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| llama-index PyPI | >= 0.12.19, < 0.12.21 | 0.12.21 |
Details and references
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code execution (RCE).
- CVSS 3.0
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- the CVSS score
- Also known as
- CVE-2025-1750