Llama-index

Latest version: v0.12.27

Vulnerabilities (7)

CVE/PVE Vulnerability ID Advisory Affected versions Severity Severity Score
CVE-2024-23751 66694

LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via …

  • <=0.9.35
CRITICAL 9.8
CVE-2023-39662 65039

An issue in llama_index v.0.7.13 and before allows a remote attacker …

  • <=0.7.13
CRITICAL 9.8
CVE-2024-12910 76255

A vulnerability in the KnowledgeBaseWebReader class of the run-llama/…

  • <0.12.9
MEDIUM 5.9
CVE-2024-12704 76267

A vulnerability in the LangChainLLM class of the run-llama/llamaindex…

  • <0.12.6
- -
CVE-2024-12909 76258

A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_in…

  • <0.12.3
- -
CVE-2024-12911 76254

A vulnerability in the default_jsonalyzer function of the JSONalyzeQu…

  • <0.12.3
- -
CVE-2024-4181 71793

A command injection vulnerability exists in the RunGptLLM class of th…

  • <0.10.13
- -