Skip to content
LlamaIndexGHSA-fxc2-8m62-m85x

LlamaIndex includes an exec call for `import {cls_name}`

Critical9.8CVE-2024-45201 · Published Aug 22, 2024 · updated Jun 29, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index-core
PyPI
< 0.10.380.10.38
Details and references

An issue was discovered in llama_index before 0.10.38. `download/integration.py` includes an exec call for `import {cls_name}`.

CVSS 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-94
Also known as
CVE-2024-45201, PYSEC-2024-192, PYSEC-2026-395

More LlamaIndex advisories

All LlamaIndex
DateAdvisory
May 162024RunGptLLM class in LlamaIndex has a command injection
CVE-2024-4181High8.8fixed in 0.10.13
Apr 162024llama-index-core Command Injection vulnerability
CVE-2024-3271Critical9.8fixed in 0.10.24
Apr 102024llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
CVE-2024-3098Critical9.8fixed in 0.10.24
Mar 202025LlamaIndex Improper Handling of Exceptional Conditions vulnerability
CVE-2024-12704High7.5fixed in 0.12.6
Mar 202025LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
CVE-2024-12911High7.1fixed in 0.12.3
Mar 202025LlamaIndex Uncontrolled Resource Consumption vulnerability
CVE-2024-12910Medium5.9fixed in 0.12.9

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.