llama-index-core vulnerabilities
CVEs whose affected-version data names the llama-index-core package (pip). Each record lists the affected and patched versions; check a specific version with the dependency checker or POST /api/sbom.
7 CVEsRSS
CVE-2025-6208Medium· 5.3llama-index-core vulnerable to Uncontrolled Resource Consumption
llama-index-core vulnerable to Uncontrolled Resource Consumption
▾ Sunlitllama-index-core · llama-index-coreEPSS 0.39%via OSV
CVE-2025-7647High· 7.3llama-index-core insecurely handles temporary files
llama-index-core insecurely handles temporary files
▾ Twilightllama-index-core · llama-index-coreEPSS 0.15%via OSV
CVE-2025-5302High· 8.6LlamaIndex affected by a Denial of Service (DOS) in JSONReader
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
▾ Twilightllama-index-core · llama-index-coreEPSS 0.29%via OSV
CVE-2025-3108Medium· 5.0LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
▾ Sunlitllama-index-core · llama-index-coreEPSS 0.43%via OSV
CVE-2025-5472Medium· 6.5LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
▾ Sunlitllama-index-core · llama-index-coreEPSS 0.34%via OSV
CVE-2025-6209High· 7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
▾ Twilightllama-index-core · llama-index-coreEPSS 0.55%via OSV
CVE-2024-12704High· 7.5LlamaIndex Improper Handling of Exceptional Conditions vulnerability
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
▾ Twilightllama-index-core · llama-index-coreEPSS 0.81%via OSV