📦 Llamaindex

by Llamaindex

🔍 What is Llamaindex?

Description coming soon...

🛡️ Security Overview

Click on a severity to filter vulnerabilities

⚠️ Known Vulnerabilities

CVE-2025-1793

CRITICAL CVSS 9.8 Jun 5, 2025

SQL injection vulnerabilities in multiple vector store integrations of run-llama/llama_index v0.12.21 allow attackers to execute arbitrary SQL commands. This can lead to unauthorized data access, modi...

CVE-2025-1750

CRITICAL CVSS 9.8 Jun 2, 2025

An SQL injection vulnerability in DuckDBVectorStore's delete function allows attackers to manipulate the ref_doc_id parameter to execute arbitrary SQL commands. This can lead to reading/writing files ...

CVE-2024-12909

CRITICAL CVSS 9.8 Mar 20, 2025

This SQL injection vulnerability in the FinanceChatLlamaPack allows attackers to execute arbitrary SQL queries through the database_agent's run_sql_query function. Exploitation can lead to remote code...

CVE-2024-11958

CRITICAL CVSS 9.8 Mar 20, 2025

A critical SQL injection vulnerability in the duckdb_retriever component of run-llama/llama_index allows attackers to execute arbitrary SQL commands. This can lead to remote code execution by installi...

CVE-2024-3271

CRITICAL CVSS 9.8 Apr 16, 2024

A command injection vulnerability in the run-llama/llama_index repository allows attackers to bypass security checks and execute arbitrary code on servers. This remote code execution vulnerability aff...

CVE-2024-23751

CRITICAL CVSS 9.8 Jan 22, 2024

This CVE describes a SQL injection vulnerability in LlamaIndex's Text-to-SQL feature that allows attackers to execute arbitrary SQL commands through natural language input. Systems using affected vers...

CVE-2025-7707

HIGH CVSS 7.8 Oct 13, 2025

The llama_index library version 0.12.33 sets the NLTK data directory to a world-writable location by default, allowing local users to tamper with or delete NLTK data files. This can lead to denial of ...

CVE-2025-6209

HIGH CVSS 7.5 Jul 7, 2025

A path traversal vulnerability in run-llama/llama_index versions 0.12.27 through 0.12.40 allows attackers to read arbitrary files on the server by manipulating the image_path input in the encode_image...

CVE-2025-3046

HIGH CVSS 7.5 Jul 7, 2025

This vulnerability allows attackers to read arbitrary files on systems using the affected llama_index library by exploiting symbolic link handling in the ObsidianReader class. Users of run-llama/llama...

CVE-2025-1752

HIGH CVSS 7.5 May 10, 2025

This CVE describes a Denial of Service vulnerability in the run-llama/llama_index project's KnowledgeBaseWebReader class. Attackers can crash Python processes by exploiting improper recursion limit ha...

CVE-2024-12911

HIGH CVSS 7.1 Mar 20, 2025

This vulnerability allows SQL injection through prompt injection in the JSONalyzeQueryEngine component of llama_index. Attackers can create arbitrary files and cause Denial-of-Service attacks. All use...

CVE-2024-12704

HIGH CVSS 7.5 Mar 20, 2025

A vulnerability in the LangChainLLM class of llama_index v0.12.5 allows denial of service attacks through infinite loops when threads terminate abnormally. This affects applications using the stream_c...

CVE-2025-6211

MEDIUM CVSS 6.5 Jul 10, 2025

This vulnerability in the run-llama/llama_index library uses MD5 hashing to generate document chunk IDs, causing hash collisions when different chunks have identical text. This leads to data loss, bro...

CVE-2025-6210

MEDIUM CVSS 6.2 Jul 7, 2025

This vulnerability in the ObsidianReader class of llama_index allows attackers to bypass path restrictions using hardlinks, potentially accessing sensitive system files like /etc/passwd. It affects us...