© 2025-2026 PySpect
First version without a known vulnerability: 0.13.0
llama-index-core vulnerable to Uncontrolled Resource Consumption
Fixed in: 0.12.41
llama-index-core insecurely handles temporary files
Fixed in: 0.13.0
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
Fixed in: 0.12.38
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
Fixed in: 0.12.41
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
Fixed in: 0.12.38
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
Fixed in: 0.12.41
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
Fixed in: 0.12.6
LlamaIndex includes an exec call for `import {cls_name}`
Fixed in: 0.10.38
llama-index-core Command Injection vulnerability
Fixed in: 0.10.24
llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
Fixed in: 0.10.24