Vulnerability index

Browse CVEs

24 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2024-14021 LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk()… Llamaindex after 0.11.6 Fix from $1,9502026-01-12 HIGH 7.5 CVE-2024-58339 LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack Va… Llamaindex after 0.12.2 Fix from $1,9502026-01-12 HIGH 7.8 CVE-2025-7707 The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-u… Llamaindex 0.13.0+ Fix from $1,9502025-10-13 MEDIUM 6.5 CVE-2025-6211 A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to genera… Llamaindex 0.3.1+ Fix from $1,6002025-07-10 HIGH 7.5 CVE-2025-6209 A path traversal vulnerability exists in run-llama/llama_index versions 0.12.27 through 0.12.40, specifically within the `encode_image` function in `… Llamaindex 0.12.41+ Fix from $1,9502025-07-07 MEDIUM 6.2 CVE-2025-6210 A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path … Llamaindex 0.5.2+ Fix from $1,6002025-07-07 MEDIUM 6.5 CVE-2025-5472 The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerabi… Llamaindex 0.12.38+ Fix from $1,6002025-07-07 HIGH 7.5 CVE-2025-3225 An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository,… Llamaindex 0.12.29+ Fix from $1,9502025-07-07 HIGH 7.5 CVE-2025-3046 A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read th… Llamaindex 0.12.28+ Fix from $1,9502025-07-07 MEDIUM 5.3 CVE-2025-3044 A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when … Llamaindex 0.12.28+ Fix from $1,6002025-07-07 HIGH 7.5 CVE-2025-3108 A critical deserialization vulnerability exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 th… Llamaindex 0.12.41+ Fix from $1,9502025-07-06 CRITICAL 9.8 CVE-2025-1793 Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attac… Llamaindex 0.12.28+ Fix from $2,3002025-06-05 CRITICAL 9.8 CVE-2025-1750 An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allow… Llamaindex 0.12.21+ Fix from $2,3002025-06-02 HIGH 7.8 CVE-2025-1753 LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files`… Llamaindex Patch available Fix from $1,9502025-05-28 HIGH 7.5 CVE-2025-1752 A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting versi… Llamaindex 0.3.6+ Fix from $1,9502025-05-10 HIGH 7.1 CVE-2024-12911 A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection v… Llamaindex 0.5.1+ Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2024-12909 A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql… Llamaindex 0.3.0+ Fix from $2,3002025-03-20 MEDIUM 5.9 CVE-2024-12910 A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial o… Llamaindex 0.12.9+ Fix from $1,6002025-03-20 HIGH 7.5 CVE-2024-12704 A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial of Service (DoS) attack. The … Llamaindex Patch available Fix from $1,9502025-03-20 CRITICAL 9.8 CVE-2024-11958 A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version.… Llamaindex 0.4.0+ Fix from $2,3002025-03-20 HIGH 8.8 CVE-2024-45201 An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}. Llamaindex 0.10.38+ Fix from $1,9502024-08-22 HIGH 8.8 CVE-2024-4181 A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI … Llamaindex 0.10.13+ Fix from $1,9502024-05-16 CRITICAL 9.8 CVE-2024-3271 A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass th… Llamaindex 0.10.26+ Fix from $2,3002024-04-16 CRITICAL 9.8 CVE-2024-23751 LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, … Llamaindex after 0.9.34 Fix from $2,3002024-01-22