Skip to content
LlamaIndexGHSA-r6gp-rff2-p3hf

llama-index-core Command Injection vulnerability

Critical9.8CVE-2024-3271 · Published Apr 16, 2024 · updated Jun 29, 2026

A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism, which checks for the presence of underscores in code generated by LLM, to execute arbitrary code. This is achieved by crafting input that does not contain an underscore but still results in the execution of OS commands. The vulnerability allows for remote code execution (RCE) on the server hosting the application.

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index-core
PyPI
< 0.10.240.10.24
Details and references

More LlamaIndex advisories

All LlamaIndex
Advisory
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
High7.5Mar 20, 2025
LlamaIndex includes an exec call for `import {cls_name}`
Critical9.8Aug 22, 2024
RunGptLLM class in LlamaIndex has a command injection
High8.8May 16, 2024
llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
Critical9.8Apr 10, 2024
SQL injection in llama-index
Critical9.8Jan 22, 2024
llama-index vulnerable to arbitrary code execution
Critical9.8Aug 15, 2023

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.