Skip to content
LlamaIndexGHSA-2xxc-73fv-36f7

llama-index vulnerable to arbitrary code execution

Critical9.8CVE-2023-39662 · Published Aug 15, 2023 · updated Sep 30, 2024

An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index
PyPI
< 0.9.140.9.14
Details and references

More LlamaIndex advisories

All LlamaIndex
Advisory
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
High7.5Mar 20, 2025
LlamaIndex includes an exec call for `import {cls_name}`
Critical9.8Aug 22, 2024
RunGptLLM class in LlamaIndex has a command injection
High8.8May 16, 2024
llama-index-core Command Injection vulnerability
Critical9.8Apr 16, 2024
llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
Critical9.8Apr 10, 2024
SQL injection in llama-index
Critical9.8Jan 22, 2024

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.