A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `database_agent`. This vulnerability can be exploited by an attacker to inject arbitrary SQL queries, leading to remote code execution (RCE) through the use of PostgreSQL's large object functionality. The issue is fixed in version 0.3.0.
CVE ID: CVE-2024-12909
CVSS Base Severity: CRITICAL
CVSS Base Score: 10.0
CVSS Vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Vendor: run-llama
Product: run-llama/llama_index
EPSS Score: 0.21% (probability of being exploited)
EPSS Percentile: 43.62% (scored less or equal to compared to others)
EPSS Date: 2025-04-18 (when was this score calculated)