Critical severity9.8NVD Advisory· Published Jan 22, 2024· Updated Jun 17, 2026
CVE-2024-23751
CVE-2024-23751
Description
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine. For example, an attacker might be able to delete this year's student records via "Drop the Students table" within English language input.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
llama-indexPyPI | <= 0.9.35 | — |
Affected products
3- LlamaIndex/llama_indexdescription
Patches
Vulnerability mechanics
References
4- github.com/run-llama/llama_index/issues/9957nvdExploitIssue TrackingVendor AdvisoryWEB
- github.com/advisories/GHSA-2jxw-4hm4-6w87ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-23751ghsaADVISORY
- github.com/pypa/advisory-database/tree/main/vulns/llama-index/PYSEC-2024-12.yamlghsaWEB
News mentions
0No linked articles in our index yet.