VulnWatch VulnWatch
← Back to dashboard
Critical github · GHSA-339r-cjv9-x78g

LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection

Published Mar 20, 2025 CVSS 9.8

A SQL injection vulnerability exists in the duckdb_retriever component of the run-llama/llama_index repository, specifically in llama-index-retrievers-duckdb-retriever prior to v0.4.0. The vulnerability arises from the construction of SQL queries without using prepared statements, allowing an attacker to inject arbitrary SQL code. This can lead to remote code execution (RCE) by installing the shellfs extension and executing malicious commands.

Affected AI Products

llamaindex llama
Get the weekly digest. Every Monday: top AI security stories of the week. Free.