{"data":{"ecosystem":"pypi","name":"llama-index-core","url":"https://aisecwatch.com/packages/pypi/llama-index-core","latestVersion":"0.14.25","firstReleaseAt":"2024-02-02T22:24:44.788Z","repository":"https://github.com/run-llama/llama_index","llm":{"exposure":"direct","depth":0,"integratedAt":"2024-02-02T22:24:44.788Z","integratedVersion":"0.9.41","sdks":["llama-index"],"path":[]},"authority":{"profile":["http"],"fromDependencies":["pypi:aiohttp","pypi:httpx","pypi:requests"]},"dependencies":[{"ecosystem":"pypi","name":"banks","versionSpec":"<3,>=2.3.0","scope":"runtime"},{"ecosystem":"pypi","name":"llama-index-workflows","versionSpec":"<3,>=2.14.0","scope":"runtime"},{"ecosystem":"pypi","name":"aiohttp","versionSpec":"<4,>=3.8.6","scope":"runtime"},{"ecosystem":"pypi","name":"aiosqlite","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"dataclasses-json","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"deprecated","versionSpec":">=1.2.9.3","scope":"runtime"},{"ecosystem":"pypi","name":"dirtyjson","versionSpec":"<2,>=1.0.8","scope":"runtime"},{"ecosystem":"pypi","name":"eval-type-backport","versionSpec":"<0.3,>=0.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"filetype","versionSpec":"<2,>=1.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"fsspec","versionSpec":">=2023.5.0","scope":"runtime"},{"ecosystem":"pypi","name":"httpx","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"nest-asyncio","versionSpec":"<2,>=1.5.8","scope":"runtime"},{"ecosystem":"pypi","name":"networkx","versionSpec":">=3.0","scope":"runtime"},{"ecosystem":"pypi","name":"nltk","versionSpec":">=3.9.3","scope":"runtime"},{"ecosystem":"pypi","name":"numpy","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pillow","versionSpec":">=9.0.0","scope":"runtime"},{"ecosystem":"pypi","name":"platformdirs","versionSpec":null,"scope":"runtime"},{"ecosystem":"pypi","name":"pydantic","versionSpec":">=2.8.0","scope":"runtime"},{"ecosystem":"pypi","name":"pyyaml","versionSpec":">=6.0.1","scope":"runtime"},{"ecosystem":"pypi","name":"requests","versionSpec":">=2.31.0","scope":"runtime"},{"ecosystem":"pypi","name":"setuptools","versionSpec":">=80.9.0","scope":"runtime"},{"ecosystem":"pypi","name":"sqlalchemy","versionSpec":">=1.4.49","scope":"runtime"},{"ecosystem":"pypi","name":"tenacity","versionSpec":"!=8.4.0,<10.0.0,>=8.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"tiktoken","versionSpec":">=0.7.0","scope":"runtime"},{"ecosystem":"pypi","name":"tinytag","versionSpec":">=2.2.0","scope":"runtime"},{"ecosystem":"pypi","name":"tqdm","versionSpec":"<5,>=4.66.1","scope":"runtime"},{"ecosystem":"pypi","name":"typing-extensions","versionSpec":">=4.5.0","scope":"runtime"},{"ecosystem":"pypi","name":"typing-inspect","versionSpec":">=0.8.0","scope":"runtime"},{"ecosystem":"pypi","name":"wrapt","versionSpec":null,"scope":"runtime"}],"advisories":[{"id":"8fdd4595-b67f-4d35-9a96-e77e38d7b2bb","url":"https://aisecwatch.com/issues/8fdd4595-b67f-4d35-9a96-e77e38d7b2bb","cveId":"CVE-2025-6208","title":"GHSA-488g-hw5f-x29p: llama-index-core vulnerable to Uncontrolled Resource Consumption","headline":null,"severity":"medium","publishedAt":"2026-02-02T12:31:14.000Z","affected":["llama-index-core@< 0.12.41 (fixed: 0.12.41)"],"epssScore":0.00421,"matchedBy":"ecosystem"},{"id":"8025f601-1d0f-4811-8ce5-9bd53d7cde4a","url":"https://aisecwatch.com/issues/8025f601-1d0f-4811-8ce5-9bd53d7cde4a","cveId":"CVE-2025-7647","title":"GHSA-cr7q-2w66-hjcm: llama-index-core insecurely handles temporary files","headline":null,"severity":"high","publishedAt":"2025-09-27T18:30:49.000Z","affected":["llama-index-core@< 0.13.0 (fixed: 0.13.0)"],"epssScore":0.00147,"matchedBy":"ecosystem"},{"id":"d1ac1a12-03f3-4aa0-869d-94864d94a986","url":"https://aisecwatch.com/issues/d1ac1a12-03f3-4aa0-869d-94864d94a986","cveId":"CVE-2025-5302","title":"GHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReader","headline":null,"severity":"high","publishedAt":"2025-08-26T00:31:13.000Z","affected":["llama-index-core@< 0.12.38 (fixed: 0.12.38)"],"epssScore":0.00285,"matchedBy":"ecosystem"},{"id":"2a5b18c5-dd37-4505-bb3e-8b4403b62b6f","url":"https://aisecwatch.com/issues/2a5b18c5-dd37-4505-bb3e-8b4403b62b6f","cveId":"CVE-2025-6209","title":"GHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image function","headline":null,"severity":"high","publishedAt":"2025-07-07T15:30:37.000Z","affected":["llama-index-core@>= 0.11.23, < 0.12.41 (fixed: 0.12.41)"],"epssScore":0.00621,"matchedBy":"ecosystem"},{"id":"96ff7aa8-34f2-45cf-a715-21d57db0dbc1","url":"https://aisecwatch.com/issues/96ff7aa8-34f2-45cf-a715-21d57db0dbc1","cveId":"CVE-2025-5472","title":"GHSA-3wxx-q3gv-pvvv: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing","headline":null,"severity":"medium","publishedAt":"2025-07-07T12:30:23.000Z","affected":["llama-index-core@< 0.12.38 (fixed: 0.12.38)"],"epssScore":0.00388,"matchedBy":"ecosystem"},{"id":"85694e4d-71d8-4e21-adb6-f2a9181a9d57","url":"https://aisecwatch.com/issues/85694e4d-71d8-4e21-adb6-f2a9181a9d57","cveId":"CVE-2025-3108","title":"GHSA-m84c-4c34-28gf: LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component","headline":null,"severity":"medium","publishedAt":"2025-07-07T00:30:18.000Z","affected":["llama-index-core@>= 0.11.15, <= 0.12.40 (fixed: 0.12.41)"],"epssScore":0.005,"matchedBy":"ecosystem"},{"id":"546ac1c0-b4f3-4bd1-927c-5c4e253e348c","url":"https://aisecwatch.com/issues/546ac1c0-b4f3-4bd1-927c-5c4e253e348c","cveId":"CVE-2024-12704","title":"CVE-2024-12704: A vulnerability in the LangChainLLM class of the run-llama/llama_index repository, version v0.12.5, allows for a Denial…","headline":"LangChainLLM denial of service through infinite loop in stream_complete","severity":"medium","publishedAt":"2025-03-20T14:15:29.383Z","affected":["llama-index-core@< 0.12.6 (fixed: 0.12.6)"],"epssScore":0.00815,"matchedBy":"ecosystem"},{"id":"b3fad615-3b92-401d-b815-a8636ffb368d","url":"https://aisecwatch.com/issues/b3fad615-3b92-401d-b815-a8636ffb368d","cveId":"CVE-2024-45201","title":"GHSA-fxc2-8m62-m85x: LlamaIndex includes an exec call for `import {cls_name}`","headline":null,"severity":"critical","publishedAt":"2024-08-22T21:31:29.000Z","affected":["llama-index-core@< 0.10.38 (fixed: 0.10.38)"],"epssScore":0.00533,"matchedBy":"ecosystem"},{"id":"8214de93-f18c-45bc-b6d5-878e3ed0eeb0","url":"https://aisecwatch.com/issues/8214de93-f18c-45bc-b6d5-878e3ed0eeb0","cveId":"CVE-2024-3271","title":"GHSA-r6gp-rff2-p3hf: llama-index-core Command Injection vulnerability","headline":null,"severity":"critical","publishedAt":"2024-04-16T00:30:34.000Z","affected":["llama-index-core@< 0.10.24 (fixed: 0.10.24)"],"epssScore":0.02886,"matchedBy":"ecosystem"},{"id":"56b68565-ec51-4e1d-8297-485a27f31d3b","url":"https://aisecwatch.com/issues/56b68565-ec51-4e1d-8297-485a27f31d3b","cveId":"CVE-2024-3098","title":"CVE-2024-3098: A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the…","headline":"llama_index code execution via prompt injection in safe_eval","severity":"high","publishedAt":"2024-04-10T17:15:56.213Z","affected":["llama-index-core@< 0.10.24 (fixed: 0.10.24)"],"epssScore":0.00959,"matchedBy":"ecosystem"}],"checkedAt":"2026-10-09T21:59:39.738Z"},"meta":{"advisoryMatching":"by package name and ecosystem; an advisory with no ecosystem recorded for the package is matched by name alone"}}