{"data":{"id":"8025f601-1d0f-4811-8ce5-9bd53d7cde4a","title":"GHSA-cr7q-2w66-hjcm: llama-index-core insecurely handles temporary files","summary":"The llama-index-core package, up to version 0.12.44, uses a predictable, hardcoded directory path, /tmp/llama_index, in its get_cache_dir() function on Linux systems without proper security controls. On multi-user Linux systems, attackers can steal proprietary models, poison cached embeddings, or conduct symlink attacks. The flaw is classified under CWE-379, CWE-377, and CWE-367.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-cr7q-2w66-hjcm","publishedAt":"2025-09-27T18:30:49.000Z","cveId":"CVE-2025-7647","cweIds":["CWE-378"],"cvssScore":"7.3","cvssSeverity":"high","severity":"high","attackType":["model_theft","rag_poisoning"],"issueType":"vulnerability","affectedPackages":["llama-index-core@< 0.13.0 (fixed: 0.13.0)"],"affectedPackageNames":["llama-index-core"],"affectedPackageRefs":["pypi:llama-index-core"],"affectedVendors":[],"affectedVendorsRaw":["llama-index-core","LlamaIndex"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L","attackVector":"local","attackComplexity":"low","privilegesRequired":"low","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00147,"epssCheckedAt":"2026-10-10T04:57:17.656Z","kevDateAdded":null,"advisoryAliases":["GHSA-cr7q-2w66-hjcm"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-09-27T18:30:49.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity"],"aiComponentTargeted":"framework","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":["AML.T0020","AML.T0051.001"]}}