Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 7.8
CVE-2024-14021
LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk()…
Llamaindex
after 0.11.6
HIGH 7.5
CVE-2024-58339
LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack Va…
Llamaindex
after 0.12.2
HIGH 7.8
CVE-2025-7707
The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-u…
Llamaindex
0.13.0+
MEDIUM 6.5
CVE-2025-6211
A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to genera…
Llamaindex
0.3.1+
HIGH 7.5
CVE-2025-6209
A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the `encode_image` function in `…
Llamaindex
0.12.41+
MEDIUM 6.2
CVE-2025-6210
A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path …
Llamaindex
0.5.2+
MEDIUM 6.5
CVE-2025-5472
The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerabi…
Llamaindex
0.12.38+
HIGH 7.5
CVE-2025-3225
An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository,…
Llamaindex
0.12.29+
HIGH 7.5
CVE-2025-3046
A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read th…
Llamaindex
0.12.28+
MEDIUM 5.3
CVE-2025-3044
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when …
Llamaindex
0.12.28+
HIGH 7.5
CVE-2025-3108
A critical deserialization vulnerability exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 th…
Llamaindex
0.12.41+
CRITICAL 9.8
CVE-2025-1793
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attac…
Llamaindex
0.12.28+
CRITICAL 9.8
CVE-2025-1750
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allow…
Llamaindex
0.12.21+
HIGH 7.8
CVE-2025-1753
LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files`…
Llamaindex
Patch available
HIGH 7.5
CVE-2025-1752
A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting versi…
Llamaindex
0.3.6+
HIGH 7.1
CVE-2024-12911
A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection v…
Llamaindex
0.5.1+
CRITICAL 9.8
CVE-2024-12909
A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql…
Llamaindex
0.3.0+
MEDIUM 5.9
CVE-2024-12910
A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial o…
Llamaindex
0.12.9+
HIGH 7.5
CVE-2024-12704
A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The …
Llamaindex
Patch available
CRITICAL 9.8
CVE-2024-11958
A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version.…
Llamaindex
0.4.0+
HIGH 8.8
CVE-2024-45201
An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}.
Llamaindex
0.10.38+
HIGH 8.8
CVE-2024-4181
A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI …
Llamaindex
0.10.13+
CRITICAL 9.8
CVE-2024-3271
A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass th…
Llamaindex
0.10.26+
CRITICAL 9.8
CVE-2024-23751
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, …
Llamaindex
after 0.9.34