Improper Control of Generation of Code ('Code Injection') Affecting llama-index package, versions [0.9.47,0.10.13)
Threat Intelligence
Exploit Maturity
Proof of concept
EPSS
0.04% (11th
percentile)
Do your applications use this vulnerable package?
In a few clicks we can analyze your entire application and see what components are vulnerable in your application, and suggest you quick fixes.
Test your applications- Snyk ID SNYK-PYTHON-LLAMAINDEX-6860338
- published 16 May 2024
- disclosed 16 May 2024
- credit Elias Hohl
Introduced: 16 May 2024
CVE-2024-4181 Open this link in a new tabHow to fix?
Upgrade llama-index
to version 0.10.13 or higher.
Overview
llama-index is an Interface between LLMs and your data
Affected versions of this package are vulnerable to Improper Control of Generation of Code ('Code Injection') in the eval
function. An attacker can execute arbitrary commands on the client's machine by exploiting this vulnerability.
References
CVSS Scores
version 3.1