CVE-2025-1793 describes multiple SQL injection vulnerabilities in various vector store integrations within run-llama/llama_index version v0.12.21. These flaws allow attackers to read and write data via SQL, potentially leading to unauthorized access to sensitive information from other users in web applications utilizing the library. Rated as Critical with a CVSS score of 9.8, the vulnerability has a low attack complexity and can result in complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion with 12 mentions, indicating awareness and potential interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 0.12.21, < 0.12.28CPE matchmatch criteria | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.