CVE-2025-1750
NONE EPSS 48.7%
Published Jun 2, 20251y ago · Modified Jun 17, 20261w ago
Published Jun 2, 2025 1y ago
Last Modified Jun 17, 2026 1w ago
Description
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code execution (RCE).
Threat Intelligence
EPSS Exploit Probability
48.7% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-89 SQL Injection Injection
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| llamaindex | llamaindex | * | ≥0.12.19 – <0.12.21 |
References 2
- github.com https://github.com/run-llama/llama_index/commit/369a2942df2efcf6b74461c45d20a0af1fbe4ae2
- huntr.com https://huntr.com/bounties/e1302233-9180-4269-9047-1526247d2cd8
Remediation
- github.com https://github.com/run-llama/llama_index/commit/369a2942df2efcf6b74461c45d20a0af1fbe4ae2