Critical severity9.8NVD Advisory· Published Mar 20, 2025· Updated Jun 17, 2026
CVE-2024-11958
CVE-2024-11958
Description
A SQL injection vulnerability exists in the duckdb_retriever component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from the construction of SQL queries without using prepared statements, allowing an attacker to inject arbitrary SQL code. This can lead to remote code execution (RCE) by installing the shellfs extension and executing malicious commands.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
llama-index-retrievers-duckdb-retrieverPyPI | < 0.4.0 | 0.4.0 |
Affected products
3- Range: unspecified
Patches
Vulnerability mechanics
References
6- github.com/run-llama/llama_index/commit/35bd221e948e40458052d30c6ef2779bc965b6d0nvdPatchWEB
- huntr.com/bounties/8ddf66e1-f74c-4d53-992b-76bc45cacac1nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-339r-cjv9-x78gghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-11958ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/llama-index-retrievers-duckdb-retriever/PYSEC-2026-399.yamlghsaWEB
- pypi.org/project/llama-index-retrievers-duckdb-retrieverghsaWEB
News mentions
0No linked articles in our index yet.