CVE-2025-7707High· 7.1▾ Twilightllama-index has Insecure Temporary File
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 39.1 · likelihood 0 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 8.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via OSV
Last analysed / modified upstream
0.2%
0.2% → 0.2%
The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data tampering, or privilege escalation. The vulnerability arises from the use of a shared cache directory instead of a user-specific one, making it susceptible to local data tampering and denial of service.
llama-index < 0.13.0Upgrade to a patched release:
llama-index 0.13.0Connected by shared product, vendor, weakness, or advisory.
CVE-2025-1793Critical· 9.8llama_index vulnerable to SQL Injection
CVE-2024-4181High· 8.8RunGptLLM class in LlamaIndex has a command injection
CVE-2024-12911High· 7.1LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
CVE-2025-1752High· 7.5LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2025-6211Medium· 6.5LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
CVE-2025-1750Critical· 9.8An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnera…