HighVulnerability
GHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image function
- Identifiers
- CVE-2025-6209GHSA-2rhq-96q8-4vjq
- Published
- Record updated
- Affected
- llama-index-core >= 0.11.23, < 0.12.41
- Fixed in
- 0.12.41
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.6%
Summary
A path traversal flaw in the `encode_image` function in `generic_utils.py` affects run-llama/llama_index versions 0.11.23 through 0.12.40. An attacker who controls the `image_path` input can use traversal sequences to read arbitrary files on the server, including sensitive system files, because the file path is not properly validated or sanitized.
Mitigation
Fixed in 0.12.41.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-index-corePyPILLM dependency since 2024-02-02 · 34 tracked dependents
Related items
- HighCVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_querySame vendor · NVD/CVE Database
- HighGHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary FileSame vendor · GitHub Advisory Database
- HighGHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReaderSame vendor · GitHub Advisory Database
- MediumGHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class Same vendor · GitHub Advisory Database
- MediumGHSA-3wxx-q3gv-pvvv: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsingSame vendor · GitHub Advisory Database