{"data":{"ecosystem":"pypi","name":"llama-index","url":"https://aisecwatch.com/packages/pypi/llama-index","latestVersion":"0.14.25","firstReleaseAt":"2023-02-16T21:37:36.084Z","repository":"https://github.com/run-llama/llama_index","llm":{"exposure":"direct","depth":0,"integratedAt":"2023-02-16T21:37:36.084Z","integratedVersion":"0.4.4.post2","sdks":["llama-index"],"path":[]},"authority":{"profile":[],"fromDependencies":[]},"dependencies":[{"ecosystem":"pypi","name":"llama-index-core","versionSpec":"<0.15.0,>=0.14.25","scope":"runtime"},{"ecosystem":"pypi","name":"llama-index-embeddings-openai","versionSpec":"<0.7,>=0.6.0","scope":"runtime"},{"ecosystem":"pypi","name":"llama-index-llms-openai","versionSpec":"<0.8,>=0.7.0","scope":"runtime"},{"ecosystem":"pypi","name":"nltk","versionSpec":">=3.9.3","scope":"runtime"}],"advisories":[{"id":"eebba78e-6c37-443b-a921-729c53c52315","url":"https://aisecwatch.com/issues/eebba78e-6c37-443b-a921-729c53c52315","cveId":"CVE-2025-7707","title":"GHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary File","headline":null,"severity":"high","publishedAt":"2025-10-13T18:31:13.000Z","affected":["llama-index@< 0.13.0 (fixed: 0.13.0)"],"epssScore":0.00186,"matchedBy":"ecosystem"},{"id":"add130a4-0cc8-42be-9bd4-ebf81354a1cb","url":"https://aisecwatch.com/issues/add130a4-0cc8-42be-9bd4-ebf81354a1cb","cveId":"CVE-2025-6211","title":"GHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class ","headline":null,"severity":"medium","publishedAt":"2025-07-10T15:31:27.000Z","affected":["llama-index@< 0.12.41 (fixed: 0.12.41)","llama-index-readers-docugami@< 0.3.1 (fixed: 0.3.1)"],"epssScore":0.00336,"matchedBy":"ecosystem"},{"id":"6f17ed7d-b05e-4b38-a0ef-d56a972b6d1a","url":"https://aisecwatch.com/issues/6f17ed7d-b05e-4b38-a0ef-d56a972b6d1a","cveId":"CVE-2025-1793","title":"GHSA-v3c8-3pr6-gr7p: llama_index vulnerable to SQL Injection","headline":null,"severity":"critical","publishedAt":"2025-06-05T06:30:26.000Z","affected":["llama-index@< 0.12.28 (fixed: 0.12.28)"],"epssScore":0.00663,"matchedBy":"ecosystem"},{"id":"2cce10ef-c527-4da1-98d8-97efff06c1bb","url":"https://aisecwatch.com/issues/2cce10ef-c527-4da1-98d8-97efff06c1bb","cveId":"CVE-2025-1752","title":"GHSA-7c85-87cp-mr6g: LlamaIndex Vulnerable to Denial of Service (DoS)","headline":null,"severity":"high","publishedAt":"2025-05-10T15:30:28.000Z","affected":["llama-index@>= 0.12.15, < 0.12.21 (fixed: 0.12.21)"],"epssScore":0.00521,"matchedBy":"ecosystem"},{"id":"12a5cada-7346-428f-8a9f-9ed5f9b95858","url":"https://aisecwatch.com/issues/12a5cada-7346-428f-8a9f-9ed5f9b95858","cveId":"CVE-2024-12910","title":"GHSA-jvpf-xf32-2w4q: LlamaIndex Uncontrolled Resource Consumption vulnerability","headline":null,"severity":"medium","publishedAt":"2025-03-20T12:32:44.000Z","affected":["llama-index@< 0.12.9 (fixed: 0.12.9)"],"epssScore":0.00685,"matchedBy":"ecosystem"},{"id":"ad8a95b4-5383-49ec-882f-d0b17e8e8e1a","url":"https://aisecwatch.com/issues/ad8a95b4-5383-49ec-882f-d0b17e8e8e1a","cveId":"CVE-2024-12911","title":"CVE-2024-12911: A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index…","headline":"llama_index SQL injection via prompt injection in JSONalyzeQueryEngine","severity":"high","publishedAt":"2025-03-20T10:15:32.083Z","affected":["llama-index@< 0.12.3 (fixed: 0.12.3)"],"epssScore":0.00512,"matchedBy":"ecosystem"},{"id":"31763d8b-5c80-443e-83af-595327947ec3","url":"https://aisecwatch.com/issues/31763d8b-5c80-443e-83af-595327947ec3","cveId":"CVE-2024-4181","title":"CVE-2024-4181: A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the…","headline":"llama_index RunGptLLM command injection via eval in LLM provider responses","severity":"critical","publishedAt":"2024-05-16T09:15:15.553Z","affected":["llama-index@< 0.10.13 (fixed: 0.10.13)","llama-index-llms-rungpt@< 0.1.3 (fixed: 0.1.3)"],"epssScore":0.02135,"matchedBy":"ecosystem"},{"id":"b0989752-7570-4997-bd0b-f375da7c7b75","url":"https://aisecwatch.com/issues/b0989752-7570-4997-bd0b-f375da7c7b75","cveId":"CVE-2024-23751","title":"CVE-2024-23751: LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine…","headline":"LlamaIndex SQL injection through Text-to-SQL query engines","severity":"critical","publishedAt":"2024-01-22T06:15:08.557Z","affected":["llama-index@<= 0.9.35"],"epssScore":0.0066,"matchedBy":"ecosystem"},{"id":"eccef2eb-baee-4907-9126-112e47bba628","url":"https://aisecwatch.com/issues/eccef2eb-baee-4907-9126-112e47bba628","cveId":"CVE-2023-39662","title":"GHSA-2xxc-73fv-36f7: llama-index vulnerable to arbitrary code execution","headline":null,"severity":"critical","publishedAt":"2023-08-15T18:31:32.000Z","affected":["llama-index@< 0.9.14 (fixed: 0.9.14)"],"epssScore":0.01492,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:59:37.877Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}