Technology · PyPI
llama-index (PyPI) vulnerabilities
Updated . Rebuilt every hour.
Junglewise Threat Intelligence has tracked 22 vulnerabilities in llama-index (PyPI): 0 in the last 7 days and 14 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2025-6211, was published on 13 July 2026.
- Last 7 days
- 0
- Last 90 days
- 14
- Critical, all time
- 1
- Exploited in the wild
- 0
About llama-index (PyPI)
LlamaIndex is a data framework for connecting custom data sources to large language models.
Latest llama-index (PyPI) vulnerabilities
- CVE-2025-6211: PYSEC-2026-2606 - LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader classlowCVSS 3EPSS 0.3%
- CVE-2025-7707: PYSEC-2026-1556 - llama-index has Insecure Temporary FilelowCVSS 3EPSS 0.2%
- CVE-2025-6209: PYSEC-2026-1558 - LlamaIndex vulnerable to Path Traversal attack through its encode_image functionlowCVSS 3EPSS 0.5%
- CVE-2025-5472: PYSEC-2026-1559 - LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsinglowCVSS 3EPSS 0.3%
- CVE-2025-6210: PYSEC-2026-1567 - LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploitlowCVSS 3EPSS 0.3%
- CVE-2025-3046: PYSEC-2026-1568 - LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader classlowCVSS 3EPSS 0.6%
- CVE-2025-3225: PYSEC-2026-1570 - LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parserlowCVSS 3EPSS 0.4%
- CVE-2025-3044: PYSEC-2026-1569 - LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisionslowCVSS 3EPSS 0.3%
- CVE-2025-3108: PYSEC-2026-1564 - LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer componentlowCVSS 3.1EPSS 0.4%
- CVE-2025-1753: PYSEC-2026-1557 - LLama-Index CLI OS command injection vulnerabilitylowCVSS 3EPSS 1.1%
- CVE-2025-1752: PYSEC-2026-1554 - LlamaIndex Vulnerable to Denial of Service (DoS)lowCVSS 3EPSS 0.5%
- CVE-2024-12911: PYSEC-2026-1555 - LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure PermissionslowCVSS 3EPSS 0.5%
- CVE-2024-12704: PYSEC-2026-1563 - LlamaIndex Improper Handling of Exceptional Conditions vulnerabilitylowCVSS 3EPSS 0.8%
- CVE-2024-4181: PYSEC-2026-1565 - RunGptLLM class in LlamaIndex has a command injectionlowCVSS 3EPSS 2.1%
- CVE-2024-45201: PYSEC-2026-395 - LlamaIndex includes an exec call for `import {cls_name}`lowCVSS 3.1EPSS 0.5%
- CVE-2024-58339: LlamaIndex resource exhaustion in VannaQueryEngine SQL executionhighCVSS 7.5EPSS 0.6%
- CVE-2024-14021: LlamaIndex unsafe deserialization in BGEM3Index load_from_diskhighCVSS 7.8EPSS 0.3%
- CVE-2025-1793: run-llama llama-index SQL injection in vector store integrationscriticalCVSS 9.8EPSS 0.7%
- CVE-2025-1750: PYSEC-2025-245 - An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index…lowCVSS 3EPSS 0.8%
- CVE-2024-12910: PYSEC-2025-11 - A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version…lowCVSS 3.1EPSS 0.7%
- CVE-2024-23751: PYSEC-2024-12 - LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in…lowCVSS 3.1EPSS 0.7%
- CVE-2023-39662: PYSEC-2023-148 - An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the…lowCVSS 3.1EPSS 1.5%
Most severe llama-index (PyPI) vulnerabilities
Exploited in the wild first, then by severity and CVSS score.
- CVE-2025-1793: run-llama llama-index SQL injection in vector store integrationscriticalCVSS 9.8EPSS 0.7%
- CVE-2024-14021: LlamaIndex unsafe deserialization in BGEM3Index load_from_diskhighCVSS 7.8EPSS 0.3%
- CVE-2024-58339: LlamaIndex resource exhaustion in VannaQueryEngine SQL executionhighCVSS 7.5EPSS 0.6%
- CVE-2023-39662: PYSEC-2023-148 - An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the…lowCVSS 3.1EPSS 1.5%
- CVE-2024-12910: PYSEC-2025-11 - A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version…lowCVSS 3.1EPSS 0.7%
- CVE-2024-23751: PYSEC-2024-12 - LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in…lowCVSS 3.1EPSS 0.7%
- CVE-2024-45201: PYSEC-2026-395 - LlamaIndex includes an exec call for `import {cls_name}`lowCVSS 3.1EPSS 0.5%
- CVE-2025-3108: PYSEC-2026-1564 - LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer componentlowCVSS 3.1EPSS 0.4%
- CVE-2024-4181: PYSEC-2026-1565 - RunGptLLM class in LlamaIndex has a command injectionlowCVSS 3EPSS 2.1%
- CVE-2025-1753: PYSEC-2026-1557 - LLama-Index CLI OS command injection vulnerabilitylowCVSS 3EPSS 1.1%
Vulnerabilities per week
The last 13 weeks, by the week each vulnerability was published.
| Week of | Bar | Vulns | Critical |
|---|---|---|---|
| 6 Jul 2026 | 13 | 0 | |
| 13 Jul 2026 | 1 | 0 | |
| 20 Jul 2026 | 0 | 0 | |
| 27 Jul 2026 | 0 | 0 | |
| 3 Aug 2026 | 0 | 0 | |
| 10 Aug 2026 | 0 | 0 | |
| 17 Aug 2026 | 0 | 0 | |
| 24 Aug 2026 | 0 | 0 | |
| 31 Aug 2026 | 0 | 0 | |
| 7 Sep 2026 | 0 | 0 | |
| 14 Sep 2026 | 0 | 0 | |
| 21 Sep 2026 | 0 | 0 | |
| 28 Sep 2026 | 0 | 0 |
How this is built
Junglewise Threat Intelligence collects vulnerabilities from NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories, and matches each one to the technologies and vendors it affects. Dates are the date a vulnerability was published, in UTC.
The pages are rebuilt from the database every hour. Frozen weekly and monthly reports never change once published, so they can be cited.
Use this data
The same data is at https://junglewise.ai/threats/technologies/llama-index.json, for scripts and language models. It is free to reuse under CC BY 4.0 with a link back to this page.
Cite as: Junglewise Threat Intelligence, "llama-index (PyPI) vulnerabilities", https://junglewise.ai/threats/technologies/llama-index, 28 September 2026.