PT-2025-12114 · Unknown · Llama Index

CVE-2024-11958

·

Published

2025-03-20

·

Updated

2026-06-29

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions run-llama/llama index versions prior to v0.4.0
Description A SQL injection vulnerability exists in the duckdb retriever component. The issue stems from constructing SQL queries without utilizing prepared statements, which allows for the injection of arbitrary SQL code. Successful exploitation can lead to remote code execution (RCE) through the installation of the shellfs extension and subsequent execution of malicious commands.
Recommendations Update to version 0.4.0 or later to resolve this issue.

Exploit

Fix

RCE

SQL injection

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2024-11958
GHSA-339R-CJV9-X78G
PYSEC-2026-399

Affected Products

Llama Index