Vulnerabilities > Llamaindex

DATE CVE VULNERABILITY TITLE RISK
2024-01-22 CVE-2024-23751 SQL Injection vulnerability in Llamaindex
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryEngine, and PGVectorSQLQueryEngine.
network
low complexity
llamaindex CWE-89
critical
9.8