Critical severity9.8NVD Advisory· Published Apr 16, 2024· Updated Jun 17, 2026
CVE-2024-3271
CVE-2024-3271
Description
A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism, which checks for the presence of underscores in code generated by LLM, to execute arbitrary code. This is achieved by crafting input that does not contain an underscore but still results in the execution of OS commands. The vulnerability allows for remote code execution (RCE) on the server hosting the application.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
llama-index-corePyPI | < 0.10.24 | 0.10.24 |
Affected products
3- Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/run-llama/llama_index/commit/5fbcb5a8b9f20f81b791c7fc8849e352613ab475nvdPatchWEB
- huntr.com/bounties/9b32490e-7cf9-470e-8d49-ba083ae7a279nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-r6gp-rff2-p3hfghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2024-3271ghsaADVISORY
- github.com/run-llama/llama_index/commit/2c92e88838a5f481d50840240b1dd3180066c6f5ghsaWEB
News mentions
0No linked articles in our index yet.