Skip to content
HighVulnerability

GHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary File

Published
Record updated
View JSON
Affected
  • llama-index < 0.13.0
Fixed in
0.13.0
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.2%

Summary

The llama_index library, version 0.12.33, sets the NLTK data directory to a subdirectory of the codebase by default. In multi-user environments that directory is world-writable, so local users can overwrite, delete, or corrupt NLTK data files. The source describes this as a shared cache directory used instead of a user-specific one.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.