Skip to content
HighVulnerability

GHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image function

Published
Record updated
View JSON
Affected
  • llama-index-core >= 0.11.23, < 0.12.41
Fixed in
0.12.41
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.6%

Summary

A path traversal flaw in the `encode_image` function in `generic_utils.py` affects run-llama/llama_index versions 0.11.23 through 0.12.40. An attacker who controls the `image_path` input can use traversal sequences to read arbitrary files on the server, including sensitive system files, because the file path is not properly validated or sanitized.

Mitigation

Fixed in 0.12.41.