Executive brief
LlamaIndex is a popular framework used by developers to connect custom data to Large Language Models (LLMs). A security flaw in how the library handles saved data files allows an attacker to execute malicious code on a user's system. This occurs if a user is tricked into loading a specially crafted index file from an untrusted source, potentially leading to a full system compromise.
Technical details
An unsafe deserialization vulnerability exists in LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 within the BGEM3Index.load_from_disk() function. The root cause is the use of the Python 'pickle' module to load the 'multi_embed_store.pkl' file from a user-provided directory without any validation. Because 'pickle' is inherently insecure for untrusted data, an attacker can craft a malicious pickle file that executes arbitrary commands when deserialized. Exploitation requires a victim to point the library to a directory controlled by the attacker; this is classified as a local attack vector with required user interaction.
Affected products
- run-llama LlamaIndex <= 0.11.6
Timeline
- 2026-01-12: disclosed: Initial disclosure via VulnCheck and NVD
- 2026-01-12: advisory