MediumVulnerability
GHSA-m84c-4c34-28gf: LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
- Identifiers
- CVE-2025-3108GHSA-m84c-4c34-28gf
- Published
- Record updated
- Affected
- llama-index-core >= 0.11.15, <= 0.12.40
- Fixed in
- 0.12.41
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.5%
Summary
The run-llama/llama_index library's JsonPickleSerializer component, in versions v0.12.27 through v0.12.40, falls back to Python's pickle module. Its deserialization calls pickle.loads(), so processing untrusted data can execute arbitrary code, and attackers can craft malicious payloads to achieve full system compromise. The root cause is an insecure fallback strategy without sufficient input validation or protective safeguards.
Mitigation
Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-index-corePyPILLM dependency since 2024-02-02 · 34 tracked dependents
Topics
Related items
- HighCVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_querySame vendor · NVD/CVE Database
- HighGHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary FileSame vendor · GitHub Advisory Database
- HighGHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReaderSame vendor · GitHub Advisory Database
- MediumGHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class Same vendor · GitHub Advisory Database
- HighGHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image functionSame vendor · GitHub Advisory Database