llamaindex
25 known vulnerabilities across versions
Vulnerabilities are listed by affected version. Select any CVE for the full briefing and its intelligence graph.
ObsidianReader class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbdefault_jsonalyzer function of the JSONalyzeQueryEngine in the run-llama/llama_index repository allowsKnowledgeBaseWebReader class of the run-llama/llama_index repository, version latest, allows an attackerduckdb_retriever component of the run-llama/llama_index repository, specifically inexec parameter in PandasQ