Back

CRITICAL

SQL Injection to RCE in run-llama/llama_index

Published Mar 20, 2025

Description

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code execution (RCE) through the use of PostgreSQL's large object functionality. The issue is fixed in version 0.3.0.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (6)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Reserved Dec 23, 2024
CISA Vulnrichment
Updated Mar 20, 2025
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner @huntr_ai
Published Mar 20, 2025
Updated Mar 20, 2025
Exploited since n/a
EUVD-2025-6982 GHSA-X48G-HM9C-WW42