Feed/CVE-2024-11958
CVE-2024-11958CRITICALCVSS 9.8

LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection

Published Mar 20, 2025·Updated Jul 21, 2026

NVD Description

A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in llama-index-retrievers-duckdb-retriever prior to v0.4.0. The vulnerability arises from the construction of SQL queries without using prepared statements, allowing an attacker to inject arbitrary SQL code. This can lead to remote code execution (RCE) by installing the shellfs extension and executing malicious commands.

Affected Packages (1)

llama-index-retrievers-duckdb-retrieverPYPI
Fixed in 0.4.0

CVSS Vector

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

References

View on NVD Search GitHub Search Google

Get alerted for CVEs like this

Register your stack and get notified within minutes when a matching CVE drops.

Start monitoring free