Skip to content

LlamaIndex security advisories

27 advisories · 4 critical or high in 12 months · latest Feb 2

27 advisories

DateAdvisory
Feb 2llama-index-core vulnerable to Uncontrolled Resource Consumption
CVE-2025-6208Medium5.3fixed in 0.12.41
Jan 12LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py. The function uses pickle.load() to deserialize multi_embed_store.pkl from a user-supplied persist_dir w
CVE-2024-14021High7.8fixed in 0.11.7
Jan 12LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query() logic generates SQL statements from a user-supplied prompt and executes them via vn.run_sql() without
CVE-2024-58339High7.5fixed in 0.12.3
Oct 132025llama-index has Insecure Temporary File
CVE-2025-7707High7.1fixed in 0.13.0
Sep 272025llama-index-core insecurely handles temporary files
CVE-2025-7647High7.3fixed in 0.13.0
Aug 262025LlamaIndex affected by a Denial of Service (DOS) in JSONReader
CVE-2025-5302High8.6fixed in 0.12.38
Jul 102025LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
CVE-2025-6211Medium6.5fixed in 0.12.41
Jul 72025LlamaIndex vulnerable to Path Traversal attack through its encode_image function
CVE-2025-6209High7.5fixed in 0.12.41
Jul 72025LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
CVE-2025-5472Medium6.5fixed in 0.12.38
Jul 72025A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. The
CVE-2025-6210Medium6.2fixed in 0.5.2
Jul 72025An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS)
CVE-2025-3225High7.5fixed in 0.12.29
Jul 72025A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other,
CVE-2025-3044Medium5.3fixed in 0.12.28
Jul 72025A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within th
CVE-2025-3046High7.5fixed in 0.12.28
Jul 72025LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-3108Medium5.0fixed in 0.12.41
Jun 52025llama_index vulnerable to SQL Injection
CVE-2025-1793Critical9.8fixed in 0.12.28
Jun 22025An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially leading to remote code
CVE-2025-1750Critical9.8fixed in 0.12.21
May 282025LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files` argument, which is directly passed into `os.system`. An attacker who controls the content of this argument can inject and execute arbitrary shell comm
CVE-2025-1753High7.8no fix yet
May 102025LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-1752High7.5fixed in 0.12.21
Mar 202025LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
CVE-2024-12911High7.1fixed in 0.12.3
Mar 202025LlamaIndex Uncontrolled Resource Consumption vulnerability
CVE-2024-12910Medium5.9fixed in 0.12.9
Mar 202025LlamaIndex Improper Handling of Exceptional Conditions vulnerability
CVE-2024-12704High7.5fixed in 0.12.6
Aug 222024LlamaIndex includes an exec call for `import {cls_name}`
CVE-2024-45201Critical9.8fixed in 0.10.38
May 162024RunGptLLM class in LlamaIndex has a command injection
CVE-2024-4181High8.8fixed in 0.10.13
Apr 162024llama-index-core Command Injection vulnerability
CVE-2024-3271Critical9.8fixed in 0.10.24
Apr 102024llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
CVE-2024-3098Critical9.8fixed in 0.10.24
Jan 222024SQL injection in llama-index
CVE-2024-23751Critical9.8no fix yet
Aug 152023llama-index vulnerable to arbitrary code execution
CVE-2023-39662Critical9.8fixed in 0.9.14
About LlamaIndex

The framework for agents over your data.

Packages watched: llama-index (PyPI), llama-index-core (PyPI).

LlamaIndex elsewhere on fru.dev: Releases · Repos

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.