Executive brief
LlamaIndex is a popular Python library for building applications that work with large language models. The ObsidianReader component, used to load data from Obsidian vault files, contains a security flaw that allows attackers to bypass file access restrictions and read sensitive system files by exploiting hardlinks. This could expose confidential data such as passwords or configuration files on affected systems.
Technical details
The vulnerability is a path traversal flaw (CWE-22) in the ObsidianReader class's load_data() method, specifically affecting llama-index versions before 0.5.2 (including 0.12.27). The root cause is inadequate handling of hardlinks during file validation—security checks fail to differentiate between regular files and hardlinks, allowing an attacker to craft hardlinks pointing to sensitive files outside the intended vault directory. No authentication is required; an attacker with local file system access can exploit this by creating malicious hardlinks within an Obsidian vault directory. The vulnerability is fixed in llama-index-readers-obsidian version 0.5.2 and later.
Affected products
- LlamaIndex llama-index-readers-obsidian before 0.5.2
Timeline
- 2025-07-07: disclosed: Vulnerability published in GitHub Advisory Database
- 2025-07-08: patched: Fix available in llama-index-readers-obsidian 0.5.2