Skip to content

[GHSA-x48g-hm9c-ww42] LlamaIndex SQL Injection vulnerability#5428

Merged
advisory-database[bot] merged 1 commit intologan-markewich/advisory-improvement-5428from
logan-markewich-GHSA-x48g-hm9c-ww42
Apr 3, 2025
Merged

[GHSA-x48g-hm9c-ww42] LlamaIndex SQL Injection vulnerability#5428
advisory-database[bot] merged 1 commit intologan-markewich/advisory-improvement-5428from
logan-markewich-GHSA-x48g-hm9c-ww42

Conversation

@logan-markewich
Copy link

Updates

  • Affected products
  • Description
  • Source code location

Comments
This CVE was incorrectly opened on the wrong package.

llama-index is a monorepo of packages. However, this CVE

  1. Incorrectly labelled the top-level llama-index package as the offending pypi package
  2. Used the wrong code version (packages are versioned independently)
  3. Used the wrong code location path

In the future, it would be greatly appreciated if CVE's on this repo pointed to the correct packages in our monorepo. Placing it incorrectly on the top-level causes a lot of headache for users when it incorrectly flags the wrong package.

@github-actions github-actions bot changed the base branch from main to logan-markewich/advisory-improvement-5428 April 2, 2025 21:45
@advisory-database advisory-database bot merged commit b4358f4 into logan-markewich/advisory-improvement-5428 Apr 3, 2025
4 checks passed
@advisory-database
Copy link
Contributor

Hi @logan-markewich! Thank you so much for contributing to the GitHub Advisory Database. This database is free, open, and accessible to all, and it's people like you who make it great. Thanks for choosing to help others. We hope you send in more contributions in the future!

@advisory-database advisory-database bot deleted the logan-markewich-GHSA-x48g-hm9c-ww42 branch April 3, 2025 13:11
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant