VulnSea

llama-index has 7 CVEs on record between 2024 and 2025. The median CVSS is 7.5 (high), with 2 rated critical. None have a confirmed exploitation report.

CVEs per month

Last 12 months, by publish date

101112010203040506070809
Exploited share
0% vs 1% corpus
Median CVSS
7.5
Publish → KEV
Last 90 days
0 prev 0

Products

  • llama-index 7
7
Total CVEs
2
Critical
0
CISA KEV
0
Exploited

llama-index vulnerabilities

CVEs affecting llama-index, newest first. Open any entry for full detail, references, and exploit status.

7 CVEsRSS

CVE-2025-7707High· 7.1
11mo ago

llama-index has Insecure Temporary File

llama-index has Insecure Temporary File

Twilightllama-index · llama-indexEPSS 0.19%via OSV
CVE-2025-6211Medium· 6.5
1y ago

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

Sunlitllama-index · llama-indexEPSS 0.32%via OSV
CVE-2025-1793Critical· 9.8
1y ago

llama_index vulnerable to SQL Injection

llama_index vulnerable to SQL Injection

Midnightllama-index · llama-indexEPSS 0.66%via OSV
CVE-2025-1750Critical· 9.8
1y ago

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnera…

An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the ref_doc_id parameter, enabling them to read and write ar…

Midnightllama-index · llama-indexEPSS 0.82%via OSV
CVE-2025-1752High· 7.5
1y ago

LlamaIndex Vulnerable to Denial of Service (DoS)

LlamaIndex Vulnerable to Denial of Service (DoS)

Twilightllama-index · llama-indexEPSS 0.50%via OSV
CVE-2024-12911High· 7.1
1y ago

LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions

LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions

Twilightllama-index · llama-indexEPSS 0.51%via OSV
CVE-2024-4181High· 8.8
2y ago

RunGptLLM class in LlamaIndex has a command injection

RunGptLLM class in LlamaIndex has a command injection

Twilightllama-index · llama-indexEPSS 2.1%via OSV
llama-index vulnerabilities (CVEs) · VulnSea