sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function
Published Sep 25, 2024
8.8
HIGHCVSS 4.0
EPSS 0.44%
Description
sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
Affected products
No data.
- 0.1.1
-
- Version 0.1.1StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| SQLite | Sqlite-Vec | n/a |
|
No Red Hat product state for this CVE.
sqlite-vec
PyPI
Introduced 0 Fixed 0.1.3sqlite-vec
npm
Introduced 0 Fixed 0.1.3sqlite-vec
RubyGems
Introduced 0 Fixed 0.1.3sqlite-vec
crates.io
Introduced 0 Fixed 0.1.3
| Ecosystem | Package | Introduced | Fixed |
|---|---|---|---|
| PyPI | sqlite-vec | 0 | 0.1.3 |
| npm | sqlite-vec | 0 | 0.1.3 |
| RubyGems | sqlite-vec | 0 | 0.1.3 |
| crates.io | sqlite-vec | 0 | 0.1.3 |
Remediation
No remediation recorded yet.
Metrics
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:H/SC:N/SI:N/SA:N
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
1 other source (CISA ADP) ▾
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
No CVSS v3.0 score for this CVE.
No CVSS v2.0 score for this CVE.
This CVE is not in the KEV list.
CISA SSVC (Vulnrichment)
Stakeholder-Specific Vulnerability Categorization from CISA ADP.
Exploitation
PoCAutomatable
YesTechnical Impact
PartialDecision
n/aAssessed Sep 25, 2024 · SSVC 2.0.3
Estimated probability of exploitation in the wild in the next 30 days (FIRST EPSS). As of Oct 1, 2026.
Score over time
2024–2026- EPSS v3
- EPSS v4
- EPSS v5
Percentile over time
- EPSS v3
- EPSS v4
- EPSS v5
Table of values (5 key points)
Flat stretches are collapsed; showing up to 120 newest points.
| Date | Score | Percentile | Model |
|---|---|---|---|
| Oct 1, 2026 | 0.44% (0.00438) | 35.75th | v5 (v2026.06.15) |
| Jun 15, 2026 | 0.43% (0.00427) | 33.84th | v5 (v2026.06.15) |
| Mar 17, 2025 | 0.16% (0.00164) | 34.88th | v4 (v2025.03.14) |
| Dec 12, 2024 | 0.04% (0.00044) | 14.68th | v3 (v2023.03.01) |
| Sep 26, 2024 | 0.04% (0.00043) | 9.59th | v3 (v2023.03.01) |
References (5)
- https://github.com/VulnSphere/LLMVulnSphere/blob/main/VectorDB/sqlite-vec/OOBR_2.md Exploit
- https://github.com/advisories/GHSA-vrcx-gx3g-j3h8 Advisory
- https://github.com/asg017/sqlite-vec/releases/tag/v0.1.3
- https://github.com/rubysec/ruby-advisory-db/blob/master/gems/sqlite-vec/CVE-2024-46488.yml
- https://nvd.nist.gov/vuln/detail/CVE-2024-46488
Change history (0)
No recorded changes yet.