VYPR

llamaindex

by Llamaindex

Source repositories

CVEs (24)

  • CVE-2025-6210MedJul 7, 2025
    risk 0.33cvss 6.2epss 0.00

    A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by…

  • CVE-2024-12910MedMar 20, 2025
    risk 0.31cvss 5.9epss 0.01

    A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the…

  • CVE-2025-3044MedJul 7, 2025
    risk 0.27cvss 5.3epss 0.00

    A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may…

  • CVE-2025-1750CriJun 2, 2025
    risk 0.00cvss 9.8epss 0.01

    An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write arbitrary files on the server, potentially…

Page 2 of 2