llama-index vulnerabilities
CVEs whose affected-version data names the llama-index package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2025-7707High· 7.1llama-index has Insecure Temporary File
llama-index has Insecure Temporary File
CVE-2025-6211Medium· 6.5LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
CVE-2025-1793Critical· 9.8llama_index vulnerable to SQL Injection
llama_index vulnerable to SQL Injection
CVE-2025-1750Critical· 9.8An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnera…
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write ar…
CVE-2025-1752High· 7.5LlamaIndex Vulnerable to Denial of Service (DoS)
LlamaIndex Vulnerable to Denial of Service (DoS)
CVE-2024-12911High· 7.1LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
CVE-2024-4181High· 8.8RunGptLLM class in LlamaIndex has a command injection
RunGptLLM class in LlamaIndex has a command injection