llama-index@0.14.12 vulnerabilities

Interface between LLMs and your data

Direct Vulnerabilities

Known vulnerabilities in the llama-index package. This does not include vulnerabilities belonging to this package’s dependencies.

Fix vulnerabilities automatically

Snyk's AI Trust Platform automatically finds the best upgrade path and integrates with your development workflows. Secure your code at zero cost.

Fix for free
VulnerabilityVulnerable Version
  • H
Deserialization of Untrusted Data

llama-index is an Interface between LLMs and your data

Affected versions of this package are vulnerable to Deserialization of Untrusted Data via the load_from_disk function. An attacker can execute arbitrary code by supplying a crafted multi_embed_store.pkl file in a user-controlled directory that is deserialized without validation.

How to fix Deserialization of Untrusted Data?

There is no fixed version for llama-index.

[0,)
  • H
Allocation of Resources Without Limits or Throttling

llama-index is an Interface between LLMs and your data

Affected versions of this package are vulnerable to Allocation of Resources Without Limits or Throttling via the custom_query function. An attacker can cause excessive CPU or memory consumption by submitting crafted prompts that generate and execute resource-intensive SQL statements.

How to fix Allocation of Resources Without Limits or Throttling?

There is no fixed version for llama-index.

[0,)