llama-index-core has 7 CVEs on record between 2025 and 2026. The median CVSS is 7.3 (high). None have a confirmed exploitation report.
CVEs per month
Last 12 months, by publish date
- Exploited share
- 0% vs 1% corpus
- Median CVSS
- 7.3
- Publish → KEV
- —
- Last 90 days
- 0 prev 0
Products
- llama-index-core 7
Worst active — by depth score
CVE-2025-5302High· 8.6LlamaIndex affected by a Denial of Service (DOS) in JSONReader47CVE-2025-6209High· 7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function41CVE-2024-12704High· 7.5LlamaIndex Improper Handling of Exceptional Conditions vulnerability41CVE-2025-7647High· 7.3llama-index-core insecurely handles temporary files40CVE-2025-5472Medium· 6.5LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing36
llama-index-core vulnerabilities
CVEs affecting llama-index-core, newest first. Open any entry for full detail, references, and exploit status.
7 CVEsRSS
CVE-2025-6208Medium· 5.3llama-index-core vulnerable to Uncontrolled Resource Consumption
llama-index-core vulnerable to Uncontrolled Resource Consumption
CVE-2025-7647High· 7.3llama-index-core insecurely handles temporary files
llama-index-core insecurely handles temporary files
CVE-2025-5302High· 8.6LlamaIndex affected by a Denial of Service (DOS) in JSONReader
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
CVE-2025-3108Medium· 5.0LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-5472Medium· 6.5LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
CVE-2025-6209High· 7.5LlamaIndex vulnerable to Path Traversal attack through its encode_image function
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
CVE-2024-12704High· 7.5LlamaIndex Improper Handling of Exceptional Conditions vulnerability
LlamaIndex Improper Handling of Exceptional Conditions vulnerability