PYSEC-2026-399

See a problem?
Import Source
https://github.com/pypa/advisory-database/blob/main/vulns/llama-index-retrievers-duckdb-retriever/PYSEC-2026-399.yaml
JSON Data
https://api.osv.dev/v1/vulns/PYSEC-2026-399
Aliases
Published
2026-06-29T11:50:35Z
Modified
2026-07-01T20:22:56Z
Severity
  • 9.8 (Critical) CVSS_V3 - CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H CVSS Calculator
Summary
LlamaIndex Retrievers Integration: DuckDBRetriever SQL Injection
Details

A SQL injection vulnerability exists in the duckdb_retriever component of the run-llama/llama_index repository, specifically in llama-index-retrievers-duckdb-retriever prior to v0.4.0. The vulnerability arises from the construction of SQL queries without using prepared statements, allowing an attacker to inject arbitrary SQL code. This can lead to remote code execution (RCE) by installing the shellfs extension and executing malicious commands.

References

Affected packages

PyPI / llama-index-retrievers-duckdb-retriever

Package

Name
llama-index-retrievers-duckdb-retriever
View open source insights on deps.dev
Purl
pkg:pypi/llama-index-retrievers-duckdb-retriever

Affected ranges

Type
ECOSYSTEM
Events
Introduced
0 Unknown introduced version / All previous versions are affected
Fixed
0.4.0

Affected versions

0.*
0.1.4
0.2.0
0.3.0

Database specific

source
"https://github.com/pypa/advisory-database/blob/main/vulns/llama-index-retrievers-duckdb-retriever/PYSEC-2026-399.yaml"