Skip to content
CriticalVulnerability

GHSA-fxc2-8m62-m85x: LlamaIndex includes an exec call for `import {cls_name}`

Published
Record updated
View JSON
Affected
  • llama-index-core < 0.10.38
Fixed in
0.10.38
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.5%

Summary

An issue in llama_index before 0.10.38 affects download/integration.py. The file contains an exec call for `import {cls_name}`, so the class name is interpolated into code that is executed.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.