VulnWatch VulnWatch
← Back to dashboard
Low osv · PYSEC-2025-245

PYSEC-2025-245

Published Jun 2, 2025 CVSS 3.0

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code execution (RCE).

Affected AI Products

llama-index
Get the weekly digest. Every Monday: top AI security stories of the week. Free.