SCA: security update for llama-index (GHSA-v3c8-3pr6-gr7p)

critical Tenable Cloud Security Plugin ID 427843

Description

There are packages installed that are affected by a vulnerability referenced in the following CVE:

- Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection
vulnerabilities. These vulnerabilities allow an attacker to read and write data using SQL, potentially
leading to unauthorized access to data of other users depending on the usage of the llama-index library in
a web application. (CVE-2025-1793)

See Also

https://github.com/advisories/GHSA-v3c8-3pr6-gr7p

Plugin Details

Severity: Critical

ID: 427843

Version: Revision 1.9

Type: Local

Family: SCA Checks

Published: 6/6/2025

Updated: 7/2/2026

Supported Sensors: Tenable Cloud Security, Tenable Self-Hosted Container Security

Risk Information

VPR

Risk Factor: Medium

Score: 4.9

Percentile: 57.58

Vendor

Vendor Severity: Critical

CVSS v2

Risk Factor: Critical

Base Score: 10

Temporal Score: 7.8

Vector: CVSS2#AV:N/AC:L/Au:N/C:C/I:C/A:C

CVSS Score Source: CVE-2025-1793

CVSS v3

Risk Factor: Critical

Base Score: 9.8

Temporal Score: 8.8

Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Temporal Vector: CVSS:3.0/E:P/RL:O/RC:C

Vulnerability Information

Exploit Available: true

Exploit Ease: Exploits are available

Patch Publication Date: 6/5/2025

Vulnerability Publication Date: 6/5/2025

Reference Information

CVE: CVE-2025-1793

cwe: CWE-89