Executive brief
A security vulnerability exists in the DuckDBRetriever component of LlamaIndex, a popular framework for building AI applications with large language models. This flaw allows an attacker to manipulate database queries to execute unauthorized commands on the underlying server. If exploited, this could lead to a complete system takeover, data theft, or service disruption.
Technical details
A SQL injection vulnerability exists in the `duckdb_retriever` component of the `llama-index-retrievers-duckdb-retriever` package. The root cause is the construction of SQL queries using string formatting or concatenation rather than prepared statements with parameterized inputs. An attacker can exploit this by providing malicious input that alters the SQL command structure. In the context of DuckDB, this can be escalated to Remote Code Execution (RCE) by using SQL commands to install the `shellfs` extension and execute arbitrary system commands. The vulnerability is reachable over the network without authentication if the retriever is exposed via an API. This issue was fixed in version 0.4.0 by implementing prepared statements.
Affected products
- LlamaIndex (run-llama) llama-index-retrievers-duckdb-retriever < 0.4.0
Timeline
- 2025-03-20: disclosed
- 2025-03-20: advisory
- 2025-03-20: patched: Fixed in version 0.4.0
References
- https://github.com/run-llama/llama_index/commit/35bd221e948e40458052d30c6ef2779bc965b6d0
- https://huntr.com/bounties/8ddf66e1-f74c-4d53-992b-76bc45cacac1
- https://github.com/pypa/advisory-database/tree/main/vulns/llama-index-retrievers-duckdb-retriever/PYSEC-2026-399.yaml
- https://github.com/run-llama/llama_index
- https://pypi.org/project/llama-index-retrievers-duckdb-retriever