CVE-2025-1750 Information

Description

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter enabling them to read and write arbitrary files on the server potentially leading to remote code execution (RCE).

Reference

https://github.com/run-llama/llama_index/commit/369a2942df2efcf6b74461c45d20a0af1fbe4ae2 https://huntr.com/bounties/e1302233-9180-4269-9047-1526247d2cd8

Share on: