LlamaIndexGHSA-fxc2-8m62-m85x
LlamaIndex includes an exec call for `import {cls_name}`
Critical9.8CVE-2024-45201 · Published Aug 22, 2024 · updated Jun 29, 2026
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| llama-index-core PyPI | < 0.10.38 | 0.10.38 |
Details and references
An issue was discovered in llama_index before 0.10.38. `download/integration.py` includes an exec call for `import {cls_name}`.
- CVSS 3.1
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- Severity from
- GitHub (reviewed advisory)
- Weakness
- CWE-94
- Also known as
- CVE-2024-45201, PYSEC-2024-192, PYSEC-2026-395
- nvd.nist.gov/vuln/detail/CVE-2024-45201
- github.com/run-llama/llama_index/pull/13523
- github.com/run-llama/llama_index/commit/bd827c30484fa085ec769fa55dc7f2add8006ac8
- github.com/pypa/advisory-database/tree/main/vulns/llama-index/PYSEC-2024-192.yaml
- github.com/run-llama/llama_index
- github.com/run-llama/llama_index/compare/v0.10.37...v0.10.38
More LlamaIndex advisories
All LlamaIndex| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| May 162024 | RunGptLLM class in LlamaIndex has a command injection CVE-2024-4181High8.8fixed in 0.10.13 | High8.8 | 0.10.13 |
| Apr 162024 | llama-index-core Command Injection vulnerability CVE-2024-3271Critical9.8fixed in 0.10.24 | Critical9.8 | 0.10.24 |
| Apr 102024 | llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution CVE-2024-3098Critical9.8fixed in 0.10.24 | Critical9.8 | 0.10.24 |
| Mar 202025 | LlamaIndex Improper Handling of Exceptional Conditions vulnerability CVE-2024-12704High7.5fixed in 0.12.6 | High7.5 | 0.12.6 |
| Mar 202025 | LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions CVE-2024-12911High7.1fixed in 0.12.3 | High7.1 | 0.12.3 |
| Mar 202025 | LlamaIndex Uncontrolled Resource Consumption vulnerability CVE-2024-12910Medium5.9fixed in 0.12.9 | Medium5.9 | 0.12.9 |