from 0, < 0.12.28
CRITICAL9.8CVE-2025-1750An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. >= 0.12.19, < 0.12.21
from 0, <= 0.9.35
CRITICAL9.8SQL injection in llama-index
from 0, < 0.9.35
CRITICAL9.8llama-index vulnerable to arbitrary code execution
from 0, < 0.9.14
CRITICAL9.8llama-index vulnerable to arbitrary code execution
from 0, < 0.7.14
HIGH8.8RunGptLLM class in LlamaIndex has a command injection
from 0, < 0.10.13
HIGH8.8RunGptLLM class in LlamaIndex has a command injection
>= 0.9.47, < 0.10.13
HIGH7.8LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_f…
from 0, < 0.11.7
HIGH7.8LLama-Index CLI OS command injection vulnerability
from 0, <= 0.12.20
HIGH7.5LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the Va…
from 0, < 0.12.3
HIGH7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function
from 0, < cdeaab91a204d1c3527f177dac37390327aef274 | >= 0.12.27, < 0.12.41
HIGH7.5LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class
>= 0.12.23, < 0.12.28
HIGH7.5LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
>= 0.12.21, < 0.12.29
HIGH7.5LlamaIndex Vulnerable to Denial of Service (DoS)
>= 0.12.15, < 0.12.21
HIGH7.5LlamaIndex Vulnerable to Denial of Service (DoS)
>= 0.12.15, < 0.12.21
HIGH7.5LlamaIndex Improper Handling of Exceptional Conditions vulnerability
from 0, <= 0.12.5
HIGH7.1llama-index has Insecure Temporary File
from 0, < 0.13.0
HIGH7.1llama-index has Insecure Temporary File
from 0, < 0.13.0
HIGH7.1LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
from 0, < 0.12.3
HIGH7.1LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
from 0, < 0.12.3
MEDIUM6.5LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
from 0, < 0.12.41
MEDIUM6.5LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
from 0, < 0.12.41
MEDIUM6.5LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
>= 0.12.28, < 0.12.38
MEDIUM6.2LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit
from 0, < 0.5.2
MEDIUM5.9LlamaIndex Uncontrolled Resource Consumption vulnerability
from 0, < 0.12.9
MEDIUM5.9LlamaIndex Uncontrolled Resource Consumption vulnerability
from 0, < 159ce485a1168100bb219dc1b93133f1121579d9 | from 0, < 0.12.9
MEDIUM5.3LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions
from 0, < 0.12.28
MEDIUM5.0LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
>= 0.12.27, < 0.12.41