{"data":{"id":"2a5b18c5-dd37-4505-bb3e-8b4403b62b6f","title":"GHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image function","summary":"A path traversal flaw in the `encode_image` function in `generic_utils.py` affects run-llama/llama_index versions 0.11.23 through 0.12.40. An attacker who controls the `image_path` input can use traversal sequences to read arbitrary files on the server, including sensitive system files, because the file path is not properly validated or sanitized.","solution":"Fixed in 0.12.41.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-2rhq-96q8-4vjq","publishedAt":"2025-07-07T15:30:37.000Z","cveId":"CVE-2025-6209","cweIds":["CWE-29"],"cvssScore":"7.5","cvssSeverity":"high","severity":"high","attackType":["other"],"issueType":"vulnerability","affectedPackages":["llama-index-core@>= 0.11.23, < 0.12.41 (fixed: 0.12.41)"],"affectedPackageNames":["llama-index-core"],"affectedPackageRefs":["pypi:llama-index-core"],"affectedVendors":["LlamaIndex"],"affectedVendorsRaw":["LlamaIndex"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00621,"epssCheckedAt":"2026-10-10T04:57:15.091Z","kevDateAdded":null,"advisoryAliases":["GHSA-2rhq-96q8-4vjq"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-07-07T15:30:37.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["confidentiality"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}