Junglewise Threat Intelligence

CVE-2024-14021: LlamaIndex unsafe deserialization in BGEM3Index load_from_disk

CVE-2024-14021 · Severity: high · CVSS 7.8 · Published 2026-01-12

Technologies: Run-Llama Llamaindex, llama-index (PyPI). Vendors: PyPI, Llamaindex.

Executive brief

LlamaIndex is a popular framework used by developers to connect custom data to Large Language Models (LLMs). A security flaw in how the library handles saved data files allows an attacker to execute malicious code on a user's system. This occurs if a user is tricked into loading a specially crafted index file from an untrusted source, potentially leading to a full system compromise.

Technical details

An unsafe deserialization vulnerability exists in LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 within the BGEM3Index.load_from_disk() function. The root cause is the use of the Python 'pickle' module to load the 'multi_embed_store.pkl' file from a user-provided directory without any validation. Because 'pickle' is inherently insecure for untrusted data, an attacker can craft a malicious pickle file that executes arbitrary commands when deserialized. Exploitation requires a victim to point the library to a directory controlled by the attacker; this is classified as a local attack vector with required user interaction.

Affected products

  • run-llama LlamaIndex <= 0.11.6

Timeline

  • 2026-01-12: disclosed: Initial disclosure via VulnCheck and NVD
  • 2026-01-12: advisory

References

Related threats