Skip to content
MediumVulnerability

GHSA-m84c-4c34-28gf: LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component

Published
Record updated
View JSON
Affected
  • llama-index-core >= 0.11.15, <= 0.12.40
Fixed in
0.12.41
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.5%

Summary

The run-llama/llama_index library's JsonPickleSerializer component, in versions v0.12.27 through v0.12.40, falls back to Python's pickle module. Its deserialization calls pickle.loads(), so processing untrusted data can execute arbitrary code, and attackers can craft malicious payloads to achieve full system compromise. The root cause is an insecure fallback strategy without sufficient input validation or protective safeguards.

Mitigation

Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things.