Vuln
·
Scope
Home
Packages
KEV
Critical
Insights
Jobs
Pricing
EN
中
Loading…
pkg:PyPI/
llama-index-core
10 total CVEs
CRITICAL
3
HIGH
4
MEDIUM
3
✅ Check your installed version
Check
All known vulnerabilities
CRITICAL
9.8
CVE-2024-45201
LlamaIndex includes an exec call for `import {cls_name}`
from 0, < 0.10.38
CRITICAL
9.8
CVE-2024-3271
llama-index-core Command Injection vulnerability
from 0, < 0.10.24
CRITICAL
9.8
CVE-2024-3098
llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
from 0, < 0.10.24
HIGH
8.6
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
from 0, < 0.12.38
HIGH
7.5
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
>= 0.11.23, < 0.12.41
HIGH
7.5
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
from 0, < 0.12.6
HIGH
7.3
llama-index-core insecurely handles temporary files
from 0, < 0.13.0
MEDIUM
6.5
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
from 0, < 0.12.38
MEDIUM
5.3
llama-index-core vulnerable to Uncontrolled Resource Consumption
from 0, < 0.12.41
MEDIUM
5.0
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
>= 0.11.15, < 0.12.41
CVE-2025-5302
CVE-2025-6209
CVE-2024-12704
CVE-2025-7647
CVE-2025-5472
CVE-2025-6208
CVE-2025-3108
PyPI/llama-index-core — 10 CVEs · VulnScope