GHSA-v3c8-3pr6-gr7p · Severity: critical · Ecosystem: pip — llama_index vulnerable to SQL Injection
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the llama-index library in a web application.
Conclusion & alert: CVE-2025-1793 is rated High Exploit Risk (60.5/100): CVSS Critical severity, with low exploitation likelihood (EPSS 0.06%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-04-01 | 0.01% | 0.06% | +0.05% |
| 2 | 2025-11-21 | 0.09% | 0.01% | -0.08% |
| 3 | 2025-11-18 | — | 0.09% | — |
Full EPSS history (6 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 9.8 | 3.0 | CRITICAL |
|
3.9 | 5.9 | [email protected] |
GHSA-v3c8-3pr6-gr7p · Severity: critical · Ecosystem: pip — llama_index vulnerable to SQL Injection
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
high | — | https://access.redhat.com/security/cve/CVE-2025-1793 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| llamaindex | llamaindex | >= 0.12.21, < 0.12.28 | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/run-llama/llama_index/commit/0008041e8dde8e519621388e5d6f558bde6ef42e | Patch |
| https://huntr.com/bounties/8cb1555a-9655-4122-b0d6-60059e79183c | Exploit Third Party Advisory |