CVE-2024-12909

CVSS 3.0 Score 10 of 10 (critical)

Details

Published Mar 20, 2025
CWE ID 89

Summary

CVE-2024-12909 is a SQL injection vulnerability affecting the FinanceChatLlamaPack in the run-llama/llama_index repository, versions up to v0.12.3. This issue resides in the `run_sql_query` function of the `database_agent`, where attackers can inject malicious SQL queries, potentially gaining remote code execution (RCE) via PostgreSQL's large object functionality. This vulnerability poses a severe risk to systems using the affected versions of the repository. The vulnerability has been addressed in version 0.3.0 of the repository.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share