CVE-2025-1750 Information
Jun 03, 2025
cve
Description
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter enabling them to read and write arbitrary files on the server potentially leading to remote code execution (RCE).
Reference
https://github.com/run-llama/llama_index/commit/369a2942df2efcf6b74461c45d20a0af1fbe4ae2 https://huntr.com/bounties/e1302233-9180-4269-9047-1526247d2cd8
Share on: