Disclosure summary
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code execution (RCE).
Source-specific records & product guidance
Sources retain their own attribution and scoring. Follow the original record to confirm affected versions, fixed releases, and configuration conditions.
GitHub Reviewed Security Advisories · GHSA-6mcc-q3mg-3qg6
Open original source · Updated Oct 02, 2026
LlamaIndex DuckDBVectorStore vulnerable to SQL injection through ref_doc_id
Source severity: CRITICAL / 0
| Ecosystem | Package | Affected range | First patched |
|---|---|---|---|
| pip | llama-index-vector-stores-duckdb | >= 0.12.19, < 0.12.21 | 0.12.21 |
Original records & references
- NIST NVD record
- CVE Program record
- github.com — Reviewed advisory
PUBLISHED 2025-06-02T08:30:33-04:00
MODIFIED 2026-10-02T18:38:37-04:00
INGESTED 2026-10-06T11:45:17-04:00