Junglewise Threat Intelligence

CVE-2025-3046: PYSEC-2026-1568 - LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

CVE-2025-3046 · Severity: low · CVSS 3 · Published 2026-07-07

Technologies: llama-index (PyPI). Vendors: PyPI.

Executive brief

LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class

Affected products

  • PyPI llama-index-readers-obsidian
  • PyPI llama-index

Related threats