0.14.10
1 years ago
9 days ago
Known vulnerabilities in the llama-index-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Insecure Temporary File due to setting the NLTK data directory to a shared, world-writable subdirectory. An attacker can overwrite, delete, or corrupt data files by exploiting the shared cache directory in a multi-user environment. How to fix Insecure Temporary File? Upgrade | [,0.12.50) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Creation of Temporary File With Insecure Permissions via the Note: This is only exploitable if multiple users share the same Linux system. How to fix Creation of Temporary File With Insecure Permissions? Upgrade | [0,0.12.50) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Uncontrolled Recursion via the How to fix Uncontrolled Recursion? Upgrade | [,0.12.38) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? Upgrade | [,0.12.41) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the How to fix Deserialization of Untrusted Data? Upgrade | [,0.12.41) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Uncontrolled Recursion via the How to fix Uncontrolled Recursion? Upgrade | [,0.12.38) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to SQL Injection through multiple vector store integrations. An attacker can read and write data using SQL, potentially leading to unauthorized access to data of other users depending on the usage of the library in a web application. How to fix SQL Injection? Upgrade | [,0.12.29) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Improper Handling of Exceptional Conditions via the How to fix Improper Handling of Exceptional Conditions? Upgrade | [,0.12.6) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to SQL Injection in the How to fix SQL Injection? Upgrade | [,0.12.3) |