{"schema_version":1,"title":"llama-index (PyPI) vulnerabilities","summary":"Junglewise Threat Intelligence has tracked 22 vulnerabilities in llama-index (PyPI): 0 in the last 7 days and 14 in the last 90 days, 1 of them critical and 0 exploited in the wild. The most recent, CVE-2025-6211, was published on 13 July 2026.","url":"https://junglewise.ai/threats/technologies/llama-index","json_url":"https://junglewise.ai/threats/technologies/llama-index.json","publisher":"Junglewise Threat Intelligence","license":"CC-BY-4.0","license_url":"https://creativecommons.org/licenses/by/4.0/","attribution":"Junglewise Threat Intelligence, https://junglewise.ai/threats/technologies/llama-index","sources":"NVD, GitHub Security Advisories, OSV, the CISA Known Exploited Vulnerabilities catalog, FIRST EPSS and vendor advisories","kind":"technology","counts":{"high":2,"all_time":22,"critical":1,"exploited":0,"last_7_days":0,"last_30_days":0,"last_90_days":14,"last_365_days":17},"latest":[{"cve":"CVE-2025-6211","cvss":3,"epss":0.0032,"slug":"cve-2025-6211-llamaindex-vulnerable-to-data-loss-through-hash-collisions-in-its","title":"PYSEC-2026-2606 - LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class","severity":"low","exploited":false,"published_at":"2026-07-13T14:36:34.041017+00:00","url":"https://junglewise.ai/threats/cve-2025-6211-llamaindex-vulnerable-to-data-loss-through-hash-collisions-in-its"},{"cve":"CVE-2025-7707","cvss":3,"epss":0.0019,"slug":"cve-2025-7707-llama-index-has-insecure-temporary-file","title":"PYSEC-2026-1556 - llama-index has Insecure Temporary File","severity":"low","exploited":false,"published_at":"2026-07-07T16:03:07.593505+00:00","url":"https://junglewise.ai/threats/cve-2025-7707-llama-index-has-insecure-temporary-file"},{"cve":"CVE-2025-6209","cvss":3,"epss":0.0055,"slug":"cve-2025-6209-llamaindex-path-traversal-in-encode-image-function","title":"PYSEC-2026-1558 - LlamaIndex vulnerable to Path Traversal attack through its encode_image function","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:57.103779+00:00","url":"https://junglewise.ai/threats/cve-2025-6209-llamaindex-path-traversal-in-encode-image-function"},{"cve":"CVE-2025-5472","cvss":3,"epss":0.0034,"slug":"cve-2025-5472-llamaindex-vulnerable-to-dos-attack-through-uncontrolled-recursive","title":"PYSEC-2026-1559 - LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:57.029091+00:00","url":"https://junglewise.ai/threats/cve-2025-5472-llamaindex-vulnerable-to-dos-attack-through-uncontrolled-recursive"},{"cve":"CVE-2025-6210","cvss":3,"epss":0.0029,"slug":"cve-2025-6210-llamaindex-obsidianreader-path-traversal-via-hardlinks","title":"PYSEC-2026-1567 - LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.96409+00:00","url":"https://junglewise.ai/threats/cve-2025-6210-llamaindex-obsidianreader-path-traversal-via-hardlinks"},{"cve":"CVE-2025-3046","cvss":3,"epss":0.0056,"slug":"cve-2025-3046-llamaindex-is-vulnerable-to-path-traversal-attack-through-its","title":"PYSEC-2026-1568 - LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.545876+00:00","url":"https://junglewise.ai/threats/cve-2025-3046-llamaindex-is-vulnerable-to-path-traversal-attack-through-its"},{"cve":"CVE-2025-3225","cvss":3,"epss":0.0042,"slug":"cve-2025-3225-llamaindex-has-an-xml-entity-expansion-vulnerability-in-its","title":"PYSEC-2026-1570 - LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.466649+00:00","url":"https://junglewise.ai/threats/cve-2025-3225-llamaindex-has-an-xml-entity-expansion-vulnerability-in-its"},{"cve":"CVE-2025-3044","cvss":3,"epss":0.0028,"slug":"cve-2025-3044-llamaindex-vulnerability-in-arxivreader-class-can-cause-md5-hash","title":"PYSEC-2026-1569 - LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.32794+00:00","url":"https://junglewise.ai/threats/cve-2025-3044-llamaindex-vulnerability-in-arxivreader-class-can-cause-md5-hash"},{"cve":"CVE-2025-3108","cvss":3.1,"epss":0.0043,"slug":"cve-2025-3108-llamaindex-has-incomplete-documentation-of-program-execution","title":"PYSEC-2026-1564 - LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.268334+00:00","url":"https://junglewise.ai/threats/cve-2025-3108-llamaindex-has-incomplete-documentation-of-program-execution"},{"cve":"CVE-2025-1753","cvss":3,"epss":0.0105,"slug":"cve-2025-1753-llama-index-cli-os-command-injection-vulnerability","title":"PYSEC-2026-1557 - LLama-Index CLI OS command injection vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:53.162697+00:00","url":"https://junglewise.ai/threats/cve-2025-1753-llama-index-cli-os-command-injection-vulnerability"},{"cve":"CVE-2025-1752","cvss":3,"epss":0.005,"slug":"cve-2025-1752-llamaindex-vulnerable-to-denial-of-service-dos","title":"PYSEC-2026-1554 - LlamaIndex Vulnerable to Denial of Service (DoS)","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:52.183037+00:00","url":"https://junglewise.ai/threats/cve-2025-1752-llamaindex-vulnerable-to-denial-of-service-dos"},{"cve":"CVE-2024-12911","cvss":3,"epss":0.0051,"slug":"cve-2024-12911-llamaindex-vulnerable-to-creation-of-temporary-file-in-directory","title":"PYSEC-2026-1555 - LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:53.683133+00:00","url":"https://junglewise.ai/threats/cve-2024-12911-llamaindex-vulnerable-to-creation-of-temporary-file-in-directory"},{"cve":"CVE-2024-12704","cvss":3,"epss":0.0082,"slug":"cve-2024-12704-llamaindex-improper-handling-of-exceptional-conditions","title":"PYSEC-2026-1563 - LlamaIndex Improper Handling of Exceptional Conditions vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T14:34:53.244852+00:00","url":"https://junglewise.ai/threats/cve-2024-12704-llamaindex-improper-handling-of-exceptional-conditions"},{"cve":"CVE-2024-4181","cvss":3,"epss":0.0214,"slug":"cve-2024-4181-rungptllm-class-in-llamaindex-has-a-command-injection","title":"PYSEC-2026-1565 - RunGptLLM class in LlamaIndex has a command injection","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:42.603795+00:00","url":"https://junglewise.ai/threats/cve-2024-4181-rungptllm-class-in-llamaindex-has-a-command-injection"},{"cve":"CVE-2024-45201","cvss":3.1,"epss":0.0053,"slug":"cve-2024-45201-llamaindex-includes-an-exec-call-for-import-cls-name","title":"PYSEC-2026-395 - LlamaIndex includes an exec call for `import {cls_name}`","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:41.215936+00:00","url":"https://junglewise.ai/threats/cve-2024-45201-llamaindex-includes-an-exec-call-for-import-cls-name"},{"cve":"CVE-2024-58339","cvss":7.5,"epss":0.0063,"slug":"cve-2024-58339-llamaindex-resource-exhaustion-in-vannaqueryengine-sql-execution","title":"LlamaIndex resource exhaustion in VannaQueryEngine SQL execution","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.63+00:00","url":"https://junglewise.ai/threats/cve-2024-58339-llamaindex-resource-exhaustion-in-vannaqueryengine-sql-execution"},{"cve":"CVE-2024-14021","cvss":7.8,"epss":0.0033,"slug":"cve-2024-14021-llamaindex-unsafe-deserialization-in-bgem3index-load-from-disk","title":"LlamaIndex unsafe deserialization in BGEM3Index load_from_disk","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.413+00:00","url":"https://junglewise.ai/threats/cve-2024-14021-llamaindex-unsafe-deserialization-in-bgem3index-load-from-disk"},{"cve":"CVE-2025-1793","cvss":9.8,"epss":0.0066,"slug":"cve-2025-1793-run-llama-llama-index-sql-injection-in-vector-store-integrations","title":"run-llama llama-index SQL injection in vector store integrations","severity":"critical","exploited":false,"published_at":"2025-06-05T06:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-1793-run-llama-llama-index-sql-injection-in-vector-store-integrations"},{"cve":"CVE-2025-1750","cvss":3,"epss":0.0082,"slug":"cve-2025-1750-pysec-2025-245-an-sql-injection-vulnerability-exists-in-the-delete","title":"PYSEC-2025-245 - An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerabil","severity":"low","exploited":false,"published_at":"2025-06-02T10:15:20.557+00:00","url":"https://junglewise.ai/threats/cve-2025-1750-pysec-2025-245-an-sql-injection-vulnerability-exists-in-the-delete"},{"cve":"CVE-2024-12910","cvss":3.1,"epss":0.0069,"slug":"cve-2024-12910-llamaindex-uncontrolled-resource-consumption-vulnerability","title":"PYSEC-2025-11 - A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:31+00:00","url":"https://junglewise.ai/threats/cve-2024-12910-llamaindex-uncontrolled-resource-consumption-vulnerability"},{"cve":"CVE-2024-23751","cvss":3.1,"epss":0.0066,"slug":"cve-2024-23751-llamaindex-sql-injection-in-text-to-sql-feature","title":"PYSEC-2024-12 - LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQuer","severity":"low","exploited":false,"published_at":"2024-01-22T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-23751-llamaindex-sql-injection-in-text-to-sql-feature"},{"cve":"CVE-2023-39662","cvss":3.1,"epss":0.0149,"slug":"cve-2023-39662-llama-index-arbitrary-code-execution-in-pandasqueryengine","title":"PYSEC-2023-148 - An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine","severity":"low","exploited":false,"published_at":"2023-08-15T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-39662-llama-index-arbitrary-code-execution-in-pandasqueryengine"}],"weekly":[{"week":"2026-07-06","critical":0,"exploited":0,"vulnerabilities":13},{"week":"2026-07-13","critical":0,"exploited":0,"vulnerabilities":1},{"week":"2026-07-20","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-07-27","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-03","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-10","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-17","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-24","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-08-31","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-07","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-14","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-21","critical":0,"exploited":0,"vulnerabilities":0},{"week":"2026-09-28","critical":0,"exploited":0,"vulnerabilities":0}],"related":[{"name":"tensorflow (PyPI)","slug":"pypi-tensorflow","vulnerabilities":428,"url":"https://junglewise.ai/threats/technologies/pypi-tensorflow"},{"name":"tensorflow-cpu (PyPI)","slug":"tensorflow-cpu","vulnerabilities":424,"url":"https://junglewise.ai/threats/technologies/tensorflow-cpu"},{"name":"tensorflow-gpu (PyPI)","slug":"tensorflow-gpu","vulnerabilities":421,"url":"https://junglewise.ai/threats/technologies/tensorflow-gpu"},{"name":"open-webui (PyPI)","slug":"open-webui","vulnerabilities":177,"url":"https://junglewise.ai/threats/technologies/open-webui"},{"name":"Django (PyPI)","slug":"django","vulnerabilities":172,"url":"https://junglewise.ai/threats/technologies/django"},{"name":"apache-airflow (PyPI)","slug":"apache-airflow","vulnerabilities":152,"url":"https://junglewise.ai/threats/technologies/apache-airflow"},{"name":"plone (PyPI)","slug":"pypi-plone","vulnerabilities":101,"url":"https://junglewise.ai/threats/technologies/pypi-plone"},{"name":"praisonai (PyPI)","slug":"pypi-praisonai","vulnerabilities":86,"url":"https://junglewise.ai/threats/technologies/pypi-praisonai"},{"name":"exiv2 (PyPI)","slug":"exiv2","vulnerabilities":85,"url":"https://junglewise.ai/threats/technologies/exiv2"},{"name":"nltk (PyPI)","slug":"nltk","vulnerabilities":83,"url":"https://junglewise.ai/threats/technologies/nltk"},{"name":"mlflow (PyPI)","slug":"mlflow","vulnerabilities":82,"url":"https://junglewise.ai/threats/technologies/mlflow"},{"name":"pillow (PyPI)","slug":"pillow","vulnerabilities":79,"url":"https://junglewise.ai/threats/technologies/pillow"}],"technology":{"hub":true,"name":"llama-index (PyPI)","slug":"llama-index","vendor":{"name":"PyPI","slug":"pypi","url":"https://junglewise.ai/threats/vendors/pypi"},"aliases":[],"homepage":"https://www.llamaindex.ai/","repo_url":"https://github.com/run-llama/llama_index","description":"LlamaIndex is a data framework for connecting custom data sources to large language models.","url":"https://junglewise.ai/threats/technologies/llama-index"},"most_severe":[{"cve":"CVE-2025-1793","cvss":9.8,"epss":0.0066,"slug":"cve-2025-1793-run-llama-llama-index-sql-injection-in-vector-store-integrations","title":"run-llama llama-index SQL injection in vector store integrations","severity":"critical","exploited":false,"published_at":"2025-06-05T06:30:26+00:00","url":"https://junglewise.ai/threats/cve-2025-1793-run-llama-llama-index-sql-injection-in-vector-store-integrations"},{"cve":"CVE-2024-14021","cvss":7.8,"epss":0.0033,"slug":"cve-2024-14021-llamaindex-unsafe-deserialization-in-bgem3index-load-from-disk","title":"LlamaIndex unsafe deserialization in BGEM3Index load_from_disk","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.413+00:00","url":"https://junglewise.ai/threats/cve-2024-14021-llamaindex-unsafe-deserialization-in-bgem3index-load-from-disk"},{"cve":"CVE-2024-58339","cvss":7.5,"epss":0.0063,"slug":"cve-2024-58339-llamaindex-resource-exhaustion-in-vannaqueryengine-sql-execution","title":"LlamaIndex resource exhaustion in VannaQueryEngine SQL execution","severity":"high","exploited":false,"published_at":"2026-01-12T23:15:51.63+00:00","url":"https://junglewise.ai/threats/cve-2024-58339-llamaindex-resource-exhaustion-in-vannaqueryengine-sql-execution"},{"cve":"CVE-2023-39662","cvss":3.1,"epss":0.0149,"slug":"cve-2023-39662-llama-index-arbitrary-code-execution-in-pandasqueryengine","title":"PYSEC-2023-148 - An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine","severity":"low","exploited":false,"published_at":"2023-08-15T17:15:00+00:00","url":"https://junglewise.ai/threats/cve-2023-39662-llama-index-arbitrary-code-execution-in-pandasqueryengine"},{"cve":"CVE-2024-12910","cvss":3.1,"epss":0.0069,"slug":"cve-2024-12910-llamaindex-uncontrolled-resource-consumption-vulnerability","title":"PYSEC-2025-11 - A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a","severity":"low","exploited":false,"published_at":"2025-03-20T10:15:31+00:00","url":"https://junglewise.ai/threats/cve-2024-12910-llamaindex-uncontrolled-resource-consumption-vulnerability"},{"cve":"CVE-2024-23751","cvss":3.1,"epss":0.0066,"slug":"cve-2024-23751-llamaindex-sql-injection-in-text-to-sql-feature","title":"PYSEC-2024-12 - LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQuer","severity":"low","exploited":false,"published_at":"2024-01-22T01:15:00+00:00","url":"https://junglewise.ai/threats/cve-2024-23751-llamaindex-sql-injection-in-text-to-sql-feature"},{"cve":"CVE-2024-45201","cvss":3.1,"epss":0.0053,"slug":"cve-2024-45201-llamaindex-includes-an-exec-call-for-import-cls-name","title":"PYSEC-2026-395 - LlamaIndex includes an exec call for `import {cls_name}`","severity":"low","exploited":false,"published_at":"2026-06-29T11:50:41.215936+00:00","url":"https://junglewise.ai/threats/cve-2024-45201-llamaindex-includes-an-exec-call-for-import-cls-name"},{"cve":"CVE-2025-3108","cvss":3.1,"epss":0.0043,"slug":"cve-2025-3108-llamaindex-has-incomplete-documentation-of-program-execution","title":"PYSEC-2026-1564 - LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:56.268334+00:00","url":"https://junglewise.ai/threats/cve-2025-3108-llamaindex-has-incomplete-documentation-of-program-execution"},{"cve":"CVE-2024-4181","cvss":3,"epss":0.0214,"slug":"cve-2024-4181-rungptllm-class-in-llamaindex-has-a-command-injection","title":"PYSEC-2026-1565 - RunGptLLM class in LlamaIndex has a command injection","severity":"low","exploited":false,"published_at":"2026-07-07T11:45:42.603795+00:00","url":"https://junglewise.ai/threats/cve-2024-4181-rungptllm-class-in-llamaindex-has-a-command-injection"},{"cve":"CVE-2025-1753","cvss":3,"epss":0.0105,"slug":"cve-2025-1753-llama-index-cli-os-command-injection-vulnerability","title":"PYSEC-2026-1557 - LLama-Index CLI OS command injection vulnerability","severity":"low","exploited":false,"published_at":"2026-07-07T16:02:53.162697+00:00","url":"https://junglewise.ai/threats/cve-2025-1753-llama-index-cli-os-command-injection-vulnerability"}],"generated_at":"2026-09-28T03:07:00.154823+00:00"}