LlamaIndexGHSA-2xxc-73fv-36f7
llama-index vulnerable to arbitrary code execution
Critical9.8CVE-2023-39662 · Published Aug 15, 2023 · updated Sep 30, 2024
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| llama-index PyPI | < 0.9.14 | 0.9.14 |
Details and references
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-74, CWE-94
- Also known as
- CVE-2023-39662, PYSEC-2023-148
- nvd.nist.gov/vuln/detail/CVE-2023-39662
- github.com/jerryjliu/llama_index/issues/7054
- github.com/run-llama/llama_index/commit/9f3e50a803f519af9ab62e63d413441c43001d81
- github.com/run-llama/llama_index/commit/aa6726706476e0f957a8d57a5ca89e519e93bad7
- github.com/jerryjliu/llama_index
- github.com/pypa/advisory-database/tree/main/vulns/llama-index/PYSEC-2023-148.yaml
More LlamaIndex advisories
All LlamaIndex| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Mar 202025 | LlamaIndex Improper Handling of Exceptional Conditions vulnerability | High7.5 | 0.12.6 |
| Aug 222024 | LlamaIndex includes an exec call for `import {cls_name}` | Critical9.8 | 0.10.38 |
| May 162024 | RunGptLLM class in LlamaIndex has a command injection | High8.8 | 0.10.13 |
| Apr 162024 | llama-index-core Command Injection vulnerability | Critical9.8 | 0.10.24 |
| Apr 102024 | llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution | Critical9.8 | 0.10.24 |
| Jan 222024 | SQL injection in llama-index | Critical9.8 | No fix yet |