VDB
CVE-2025-1793
CVE-2025-1793
PUBLISHED
CVSS 9.800000190734863 CRITICAL
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.
EPSS 0.06% · 18.0th percentile
Risk Scores
CVSS v3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.06%
18.0th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| PyPI | llama-index | 0 |
| llamaindex | llamaindex | 0.12.21 |
| run-llama | run-llama/llama_index | unspecified |
Timeline
- Jun 5, 2025 CVE Published
- Jun 5, 2025 EPSS Score
- Jun 5, 2025 PoC Published
- Jun 5, 2025 PoC Published
- Jun 5, 2025 PoC Published
- Jun 6, 2025 CVE Updated
- Jun 9, 2025 PoC Published
- Jun 16, 2025 EPSS Score
- Jun 17, 2025 Coalition ESS Score
- Jun 20, 2025 Coalition ESS Score
- Jun 26, 2025 EPSS Score
- Jul 7, 2025 EPSS Score