CVE-2024-11958
CVSS 3.0 Score 9.8 of 10 (critical)
Details
Published Mar 20, 2025
CWE ID 89
Summary
CVE-2024-11958 is a newly disclosed SQL injection vulnerability affecting the `duckdb_retriever` component in the latest version of run-llama/llama_index repository. The flaw lies in the construction of SQL queries without utilizing prepared statements, making it susceptible to SQL injection attacks. An attacker can leverage this vulnerability to inject malicious SQL code, potentially resulting in remote code execution (RCE). This can ultimately lead to the installation and execution of the dangerous shellfs extension, posing a significant security risk.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.