0.14.10
1 years ago
9 days ago
Known vulnerabilities in the llama-index-core package. This does not include vulnerabilities belonging to this package’s dependencies.
Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.
Fix for free| Vulnerability | Vulnerable Version |
|---|---|
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Insecure Temporary File due to setting the NLTK data directory to a shared, world-writable subdirectory. An attacker can overwrite, delete, or corrupt data files by exploiting the shared cache directory in a multi-user environment. How to fix Insecure Temporary File? Upgrade | [,0.12.50) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Creation of Temporary File With Insecure Permissions via the Note: This is only exploitable if multiple users share the same Linux system. How to fix Creation of Temporary File With Insecure Permissions? Upgrade | [0,0.12.50) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Uncontrolled Recursion via the How to fix Uncontrolled Recursion? Upgrade | [,0.12.38) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) via the How to fix Arbitrary File Write via Archive Extraction (Zip Slip)? Upgrade | [,0.12.41) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the How to fix Deserialization of Untrusted Data? Upgrade | [,0.12.41) |
llama-index-core is an Interface between LLMs and your data Affected versions of this package are vulnerable to Uncontrolled Recursion via the How to fix Uncontrolled Recursion? Upgrade | [,0.12.38) |