CriticalVulnerability
GHSA-v3c8-3pr6-gr7p: llama_index vulnerable to SQL Injection
- Identifiers
- CVE-2025-1793GHSA-v3c8-3pr6-gr7p
- Published
- Record updated
- Affected
- llama-index < 0.12.28
- Fixed in
- 0.12.28
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.7%
Summary
Multiple vector store integrations in run-llama/llama_index version v0.12.21 contain SQL injection vulnerabilities. An attacker can read and write data using SQL, which may expose the data of other users depending on how the llama-index library is used in a web application.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-indexPyPILLM dependency since 2023-02-16 · 12 tracked dependents
Related items
- HighCVE-2026-106119: LangChain MongoDBChatMessageHistory query injection via session identifierSame vendor · NVD/CVE Database
- LowGHSA-5x6v-p487-7qh2: LangChain: RediSearch Filter Injection via Unescaped Tag/Text ValuesSame vendor · GitHub Advisory Database
- HighGHSA-fvww-7h3r-vfhp: LangGraph SDK custom auth silently ignores actions= on resource decoratorsSame vendor · GitHub Advisory Database
- HighCVE-2026-72848: SitemapLoader nested sitemap entries bypass restrict_to_same_domainSame vendor · NVD/CVE Database
- HighGHSA-533j-2v4q-mw5h: LangChain MongoDB has NoSQL Operator Injection in MongoDBSaver.list() leading to cross-tenant data exposureSame vendor · GitHub Advisory Database