Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

CVE-2025-1793

31
FAUCET Score

CVE-2025-1793 describes multiple SQL injection vulnerabilities in various vector store integrations within run-llama/llama_index version v0.12.21. These flaws allow attackers to read and write data via SQL, potentially leading to unauthorized access to sensitive information from other users in web applications utilizing the library. Rated as Critical with a CVSS score of 9.8, the vulnerability has a low attack complexity and can result in complete compromise of confidentiality, integrity, and availability. While there is no known active exploitation or public exploit code (Metasploit, Nuclei, ExploitDB), the CVE has garnered significant community discussion with 12 mentions, indicating awareness and potential interest.

Impacted Technologies

VendorProductVersion(s)CPE
>= 0.12.21, < 0.12.28CPE matchmatch criteria
cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:*

CVSS Data

CVSS version used by this source: 3.0

9.8CRITICAL

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
UNCHANGED
Confidentiality Impact
HIGH
Integrity Impact
HIGH
Availability Impact
HIGH
Exploitability Score
3.9
Impact Score
5.9
CvssVersion
3.0

Exploit Intelligence

EPSS Score
0.58%
Probability of exploitation in next 30 days
EPSS Percentile
44.3%
Percentile rank of EPSS score among Peer Group
As of 2026-07-27
Model: v2026.06.15
This CVE's current EPSS score of 0.0058 is in the 24th percentile among its peer group of 36,862 CVEs.

Social Chatter

The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.

Media Mentions

No media coverage found for this CVE.

The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.

Remediation

Patch Available

Vendor Patches (2)

github_advisorypatch availablevia nvd_reference
View patch
pippatch availablevia ghsa
Product: llama-indexFixed in: 0.12.28

Vendor Advisories (2)

pipGHSA-v3c8-3pr6-gr7pcritical

llama_index vulnerable to SQL Injection

Jun 5, 2025
redhatCVE-2025-1793Important

llama-index: LlamaIndex SQL Injection Vulnerability

Jun 5, 2025

References

github.com / run-llama/llama_index/commit/0008041e8dde8e519621388e5d6f558bde6ef42e
Patch
huntr.com / bounties/8cb1555a-9655-4122-b0d6-60059e79183c
ExploitThird Party Advisory