Skip to content
CriticalVulnerability

GHSA-v3c8-3pr6-gr7p: llama_index vulnerable to SQL Injection

Published
Record updated
View JSON
Affected
  • llama-index < 0.12.28
Fixed in
0.12.28
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

Multiple vector store integrations in run-llama/llama_index version v0.12.21 contain SQL injection vulnerabilities. An attacker can read and write data using SQL, which may expose the data of other users depending on how the llama-index library is used in a web application.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.