Llamaindex
This hub aggregates every CVE we track for Llamaindex, a product in the ai ml space. Use it to gauge the current risk picture and drill into individual advisories.
AI / MLother
26
CVEs tracked
7
Critical
14
High
0
In CISA KEV
Severity distribution
HIGH14CRITICAL7MEDIUM5
Monthly trend
0
0
0
0
0
0
5
0
2
2
8
0
1
1
0
0
2
0
0
0
0
0
0
0
2024-092026-08
Latest CVEs
The 15 most recently published vulnerabilities affecting Llamaindex.
- CVE-2024-14021LlamaIndex <= 0.11.6 BGEM3Index Unsafe Deserialization7.8
- CVE-2024-58339LlamaIndex <= 0.12.2 VannaQueryEngine SQL Execution Allows Resource Exhaustion7.5
- CVE-2025-7707World-Writable NLTK Cache Directory Vulnerability in run-llama/llama_index7.8
- CVE-2025-7647Insecure Temporary File Handling in run-llama/llama_index7.3
- CVE-2025-6211MD5 Hash Collision in run-llama/llama_index6.5
- CVE-2025-6209Arbitrary File Read through Path Traversal in run-llama/llama_index7.5
- CVE-2025-5472Denial of Service via Uncontrolled Recursive JSON Parsing in JSONReader in run-llama/llama_index6.5
- CVE-2025-6210Hardlink-Based Path Traversal in run-llama/llama_index6.2
- CVE-2025-3046Path Traversal via Symbolic Links in run-llama/llama_index7.5
- CVE-2025-3044MD5 Hash Collision in run-llama/llama_index5.3
- CVE-2025-3225XML Entity Expansion vulnerability in run-llama/llama_index7.5
- CVE-2025-3108Unsafe Deserialization in JsonPickleSerializer Enables Remote Code Execution in run-llama/llama_index7.5
- CVE-2025-1793SQL Injection in run-llama/llama_index9.8
- CVE-2025-1750SQL Injection in run-llama/llama_index9.8
- CVE-2025-1753Command Injection in LLama-Index CLI in run-llama/llama_index7.8
Product normalization is registry-driven with AI assist and human review. How it works