CVE-2025-1750: Llamaindex
Critical severity, CVSS 9.8. EPSS: 0.8% chance of exploitation in the next 30 days.
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code execution (RCE).
Affected products
- Llamaindex Llamaindex: from 0.12.19, before 0.12.21 (fixed in 0.12.21)
Published 2025-06-02. Last modified 2026-06-17.