llama-index-readers-obsidian@0.1.1 vulnerabilities

llama-index readers obsidian integration

  • latest version

    0.5.2

  • latest non vulnerable version

  • first published

    1 years ago

  • latest version published

    1 months ago

  • licenses detected

  • Direct Vulnerabilities

    Known vulnerabilities in the llama-index-readers-obsidian package. This does not include vulnerabilities belonging to this package’s dependencies.

    How to fix?

    Automatically find and fix vulnerabilities affecting your projects. Snyk scans for vulnerabilities and provides fixes for free.

    Fix for free
    VulnerabilityVulnerable Version
    • M
    Directory Traversal

    llama-index-readers-obsidian is a llama-index readers obsidian integration

    Affected versions of this package are vulnerable to Directory Traversal via the load_data method in the ObsidianReader class. An attacker can access sensitive system files by exploiting hardlinks to bypass path restrictions.

    How to fix Directory Traversal?

    Upgrade llama-index-readers-obsidian to version 0.5.2 or higher.

    [,0.5.2)
    • H
    Directory Traversal

    llama-index-readers-obsidian is a llama-index readers obsidian integration

    Affected versions of this package are vulnerable to Directory Traversal via the ObsidianReader process. An attacker can access arbitrary files outside the intended directory by creating symbolic links that point to sensitive files, which are then processed as valid Markdown files.

    How to fix Directory Traversal?

    Upgrade llama-index-readers-obsidian to version 0.5.1 or higher.

    [,0.5.1)