Executive brief
llama-index is a popular Python library for working with large language models and structured data. The PandasQueryEngine component, which processes data queries, fails to properly validate user input in its exec parameter, allowing attackers to inject and execute arbitrary Python code directly on the server. This could lead to full system compromise, data theft, or service disruption.
Technical details
The vulnerability is a code injection issue (CWE-74, CWE-94) in the PandasQueryEngine function's exec parameter. The vulnerable code path allows unsanitized user input to be passed directly to Python's exec() function, enabling arbitrary code execution without authentication. The attack vector is network-based with no user interaction required. An attacker can gain remote code execution on any system running a vulnerable version of llama-index that exposes the PandasQueryEngine to untrusted input. Patches are available in version 0.9.14 and later.
Affected products
- LlamaIndex llama-index 0.0 to 0.9.13
Timeline
- 2023-08-15: disclosed
- 2023-08-15: patched: Fixed in version 0.9.14