Skip to content
CriticalVulnerability

GHSA-2xxc-73fv-36f7: llama-index vulnerable to arbitrary code execution

Published
Record updated
View JSON
Affected
  • llama-index < 0.9.14
Fixed in
0.9.14
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
1.5%

Summary

An issue in llama_index v0.7.13 and earlier lets a remote attacker execute arbitrary code through the `exec` parameter in the PandasQueryEngine function. The source describes the flaw and its impact but gives no further detail on exploitation conditions.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.