HighVulnerability
GHSA-cr7q-2w66-hjcm: llama-index-core insecurely handles temporary files
- Identifiers
- CVE-2025-7647GHSA-cr7q-2w66-hjcm
- Published
- Record updated
- Affected
- llama-index-core < 0.13.0
- Fixed in
- 0.13.0
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.1%
Summary
The llama-index-core package, up to version 0.12.44, uses a predictable, hardcoded directory path, /tmp/llama_index, in its get_cache_dir() function on Linux systems without proper security controls. On multi-user Linux systems, attackers can steal proprietary models, poison cached embeddings, or conduct symlink attacks. The flaw is classified under CWE-379, CWE-377, and CWE-367.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-index-corePyPILLM dependency since 2024-02-02 · 34 tracked dependents
Related items
- InfoPoster: A Preliminary Study of LLM Distillation InferenceSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)
- InfoA Security Meta-Model for Retrieval-Augmented Generation SystemsSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)
- InfoAnytime-valid detection of LLM weight exfiltrationSimilar attack · Arxiv (cs.CR + cs.CL + cs.LG)
- LowOpenAI Disrupts Reasoning Extraction Campaign Linked to Moonshot AI AssociatesSimilar attack · The Hacker News
- InfoAI race heats up as OpenAI flags alleged model-copying campaignSimilar attack · CNBC Technology