sqlite-vec v0.1.1 was discovered to contain a heap buffer overflow via the npy_token_next function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted file.
| Package (Ecosystem) | Introduced | Fixed | Limit |
|---|---|---|---|
| sqlite-vec(PyPI) | 0 | 0.1.3 | N/A |
| sqlite-vec(npm) | 0 | 0.1.3 | N/A |
| sqlite-vec(RubyGems) | 0 | 0.1.3 | N/A |
| sqlite-vec(crates.io) | 0 | 0.1.3 | N/A |
CVSS Metrics