CVE-2024-11958 is a critical SQL injection vulnerability in the duckdb_retriever component of the run-llama/llama_index repository, affecting all versions of llamaindex. This flaw allows attackers to inject arbitrary SQL code due to the absence of prepared statements, potentially leading to remote code execution (RCE) by leveraging the shellfs extension. With a CVSS score of 9.8 (CRITICAL), it presents a severe risk as it requires no user interaction or privileges and has high impact on confidentiality, integrity, and availability. Despite its high severity and FAUCET Risk Score of 89/100, there is currently no evidence of active exploitation, public exploit code, or significant community discussion.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 0.4.0CPE matchmatch criteria | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.