Description
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code execution (RCE).
Problem types
CWE-89 Improper Neutralization of Special Elements used in an SQL Command
Product status
References
huntr.com/bounties/e1302233-9180-4269-9047-1526247d2cd8
github.com/...ommit/369a2942df2efcf6b74461c45d20a0af1fbe4ae2