CVE-2025-6209
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
7.5
HIGH
CVSS 3.1
EPSS 0.55%
描述
A path traversal vulnerability exists in run-llama/llama_index versions 0.11.23 through 0.12.40, specifically within the `encode_image` function in `generic_utils.py`. This vulnerability allows an attacker to manipulate the `image_path` input to read arbitrary files on the server, including sensitive system files. The issue arises due to improper validation or sanitization of the file path, enabling path traversal sequences to access files outside the intended directory. The vulnerability is fixed in version 0.12.41.
如何修補 CVE-2025-6209
要修補 CVE-2025-6209,請將受影響套件升級到下列已修補版本。
- —升級至 cdeaab91a204d1c3527f177dac37390327aef274 或更新版本
- —升級至 0.12.41 或更新版本
- —升級至 0.12.41 或更新版本
CVE-2025-6209 正在被利用嗎?
低 — EPSS 為 0.5%,目前沒有觀察到大規模利用活動。
受影響套件(3)
- from 0, < cdeaab91a204d1c3527f177dac37390327aef274 | >= 0.12.27, < 0.12.41
- >= 0.11.23, < 0.12.41
- >= 0.11.23, < 0.12.41
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.5 | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |