{"data":{"id":"8214de93-f18c-45bc-b6d5-878e3ed0eeb0","title":"GHSA-r6gp-rff2-p3hf: llama-index-core Command Injection vulnerability","summary":"A command injection flaw in the safe_eval function of the run-llama/llama_index repository lets attackers bypass its check for underscores in LLM-generated code. Crafted input without an underscore can still run OS commands, enabling remote code execution on the server hosting the application.","solution":"N/A -- no mitigation discussed in source.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-r6gp-rff2-p3hf","publishedAt":"2024-04-16T00:30:34.000Z","cveId":"CVE-2024-3271","cweIds":["CWE-77"],"cvssScore":"9.8","cvssSeverity":"critical","severity":"critical","attackType":["jailbreak","other"],"issueType":"vulnerability","affectedPackages":["llama-index-core@< 0.10.24 (fixed: 0.10.24)"],"affectedPackageNames":["llama-index-core"],"affectedPackageRefs":["pypi:llama-index-core"],"affectedVendors":[],"affectedVendorsRaw":["llama-index-core","LlamaIndex"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.02886,"epssCheckedAt":"2026-10-10T04:57:07.748Z","kevDateAdded":null,"advisoryAliases":["GHSA-r6gp-rff2-p3hf"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2024-04-16T00:30:34.000Z","capecIds":["CAPEC-88"],"crossRefCount":0,"attackSophistication":"moderate","impactType":["confidentiality","integrity","availability"],"aiComponentTargeted":"framework","llmSpecific":true,"classifierConfidence":0.95,"researchCategory":null,"atlasIds":null}}