CVE-2025-7707
llama-index has Insecure Temporary File
7.1
HIGH
CVSS 3.1
EPSS 0.17%
描述
The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data tampering, or privilege escalation. The vulnerability arises from the use of a shared cache directory instead of a user-specific one, making it susceptible to local data tampering and denial of service.
如何修補 CVE-2025-7707
要修補 CVE-2025-7707,請將受影響套件升級到下列已修補版本。
- —升級至 0.13.0 或更新版本
- —升級至 0.13.0 或更新版本
CVE-2025-7707 正在被利用嗎?
低 — EPSS 為 0.2%,目前沒有觀察到大規模利用活動。
受影響套件(2)
- from 0, < 0.13.0
- from 0, < 0.13.0
CVSS 分數
| 來源 | 版本 | 嚴重程度 | 向量 |
|---|---|---|---|
| osv | CVSS 3.1 | HIGH7.1 | CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H |