CriticalVulnerabilityLLM-specific
GHSA-r6gp-rff2-p3hf: llama-index-core Command Injection vulnerability
- Identifiers
- CVE-2024-3271GHSA-r6gp-rff2-p3hf
- Published
- Record updated
- Affected
- llama-index-core < 0.10.24
- Fixed in
- 0.10.24
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 2.9%
Summary
A command injection flaw in the safe_eval function of the run-llama/llama_index repository lets attackers bypass its check for underscores in LLM-generated code. Crafted input without an underscore can still run OS commands, enabling remote code execution on the server hosting the application.
Mitigation
The source does not state a fix yet. Check the original advisory for updates.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-index-corePyPILLM dependency since 2024-02-02 · 34 tracked dependents
Related items
- LowAnthropic Cuts Live Internet Access for Internal AI Tests After Claude Exploits Injection FlawsSimilar attack · The Hacker News
- CriticalCVE-2026-108263: Astron Agent code-node execution as root through workflow run endpointsSimilar attack · NVD/CVE Database
- MediumHackers abuse Google Ads, Bing redirects to push Claude ClickFix attacksSimilar attack · BleepingComputer
- CriticalHermes Agent - PKCE Session Takeover via Redirect-URI Parser ConfusionSimilar attack · Tenable Research Advisories
- LowSocial Engineering AI Agents: The New BEC for 2026Similar attack · Dark Reading