CVE-2026-85689: llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses ...

Added to the CISA Known Exploited Vulnerabilities catalog on 04 Sep 2026. Vendor: AI/ML. Product: LLM. CVSS score: 6.5.

llmware 0.4.6 contains an SQL injection vulnerability in the collection-database layer (llmware/resources.py) where filter and lookup values are directly string-interpolated into SQL WHERE clauses without parameterization or escaping, in both the SQLite and PostgreSQL backends. The filter validat...

Required action: Review and patch if applicable to your AI infrastructure.