CVE-2024-12909

Source
https://nvd.nist.gov/vuln/detail/CVE-2024-12909
Import Source
https://storage.googleapis.com/osv-test-cve-osv-conversion/osv-output/CVE-2024-12909.json
JSON Data
https://api.test.osv.dev/v1/vulns/CVE-2024-12909
Aliases
Published
2025-03-20T10:15:31Z
Modified
2025-03-21T19:15:03.513825Z
Summary
[none]
Details

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the run_sql_query function of the database_agent. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code execution (RCE) through the use of PostgreSQL's large object functionality. The issue is fixed in version 0.3.0.

References

Affected packages

Git / github.com/run-llama/llama_index

Affected ranges

Type
GIT
Repo
https://github.com/run-llama/llama_index
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed