VDB

CVE-2025-1793

CVE-2025-1793 PUBLISHED CVSS 9.800000190734863 CRITICAL

Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.

EPSS 0.06% · 18.0th percentile

Risk Scores

CVSS v3.0
9.800000190734863
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
EPSS Score
0.06%
18.0th percentile

Affected Products

VendorProductVersions
PyPIllama-index0
llamaindexllamaindex0.12.21
run-llamarun-llama/llama_indexunspecified

Timeline

  • Jun 5, 2025 CVE Published
  • Jun 5, 2025 EPSS Score
  • Jun 5, 2025 PoC Published
  • Jun 5, 2025 PoC Published
  • Jun 5, 2025 PoC Published
  • Jun 6, 2025 CVE Updated
  • Jun 9, 2025 PoC Published
  • Jun 16, 2025 EPSS Score
  • Jun 17, 2025 Coalition ESS Score
  • Jun 20, 2025 Coalition ESS Score
  • Jun 26, 2025 EPSS Score
  • Jul 7, 2025 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›