PT-2025-12114 · Unknown · Llama Index

Published

2025-03-20

·

Updated

2025-07-29

·

CVE-2024-11958

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions run-llama/llama index versions prior to v0.4.0
Description A SQL injection vulnerability exists in the duckdb retriever component. The issue stems from constructing SQL queries without utilizing prepared statements, which allows for the injection of arbitrary SQL code. Successful exploitation can lead to remote code execution (RCE) through the installation of the shellfs extension and subsequent execution of malicious commands.
Recommendations Update to version 0.4.0 or later to resolve this issue.

Exploit

Fix

RCE

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-11958
GHSA-339R-CJV9-X78G

Affected Products

Llama Index