Skip to content
LlamaIndexGHSA-m84c-4c34-28gf

LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

Medium5.0CVE-2025-3108 · Published Jul 7, 2025 · updated Jul 13, 2026

Incomplete Documentation of Program Execution exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 through v0.12.40. This vulnerability allows remote code execution due to an insecure fallback to Python's pickle module. JsonPickleSerializer prioritizes deserialization using pickle.loads(), which can execute arbitrary code when processing untrusted data. Attackers can exploit this by crafting malicious payloads to achieve full system compromise. The root cause involves the use of an insecure fallback strategy without sufficient input validation or protective safeguards. Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things.

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index-core
PyPI
>= 0.11.15, < 0.12.410.12.41
Details and references

More LlamaIndex advisories

All LlamaIndex
Advisory
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
High7.5Jul 7, 2025
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Medium6.5Jul 7, 2025
LlamaIndex: path traversal
Medium6.2Jul 7, 2025
LlamaIndex: denial of service
High7.5Jul 7, 2025
A vulnerability in the ArxivReader class of the run-llama/llama_index repository
Medium5.3Jul 7, 2025
LlamaIndex: arbitrary file read
High7.5Jul 7, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.