llama-index-core
LlamaIndex is the leading document agent and OCR platform
Activity
- Latest release
- 3w ago
- Total releases
- 257
- Cadence
- ~6 days
- Last 12 months
- 20
Reach
- Stars
- 52.0k
Details
- License
- MIT
- First release
- Feb 02, 2024
| Version | Released | |
|---|---|---|
0.14.24
patch
| ||
0.14.23
patch
| ||
0.14.22
patch
| ||
0.14.21
patch
| ||
0.14.20
patch
| ||
0.14.19
patch
| ||
0.14.18
patch
| ||
0.14.17
patch
| ||
0.14.16
patch
| ||
0.14.15
patch
| ||
0.14.14
patch
| ||
0.14.13
patch
| ||
0.14.12
patch
| ||
0.14.10
patch
| ||
0.14.9
patch
| ||
0.14.8
patch
| ||
0.14.7
patch
| ||
0.14.6
patch
| ||
0.14.5
patch
| ||
0.14.4
patch
| ||
0.14.3
patch
| ||
0.14.2
patch
| ||
0.14.1
patch
| ||
0.14.0
minor
| ||
0.13.6
patch
| ||
0.13.5
patch
| ||
0.13.4
patch
| ||
0.13.3
patch
| ||
0.13.2
patch
| ||
0.13.1
patch
| ||
0.13.0
minor
| ||
0.12.52.post1
pre
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.52
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.51
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.50
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.49
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.48
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.47
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.46
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.45
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.44
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.43
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.42
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.41
patch
1 CVE
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev | ||
0.12.40
patch
4 CVEs
CVE-2025-6208
PYSEC-2026-1560
GHSA-488g-hw5f-x29p
Jul 07, 2026
llama-index-core vulnerable to Uncontrolled Resource Consumption
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 201 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6209
PYSEC-2026-1558
GHSA-2rhq-96q8-4vjq
PYSEC-2025-65
Jul 07, 2026
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A path traversal vulnerability exists in run-llama/llama_index versions 0.11.23 through 0.12.40, specifically within the Affected versions
0.11.23
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
+ 45 more Show less
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-3108
PYSEC-2026-1564
GHSA-m84c-4c34-28gf
PYSEC-2025-249
Jul 07, 2026
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
Incomplete Documentation of Program Execution exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 through v0.12.40. This vulnerability allows remote code execution due to an insecure fallback to Python's pickle module. JsonPickleSerializer prioritizes deserialization using pickle.loads(), which can execute arbitrary code when processing untrusted data. Attackers can exploit this by crafting malicious payloads to achieve full system compromise. The root cause involves the use of an insecure fallback strategy without sufficient input validation or protective safeguards. Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things. Affected versions
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.12.0
0.12.1
0.12.10
+ 53 more Show less
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.39
patch
4 CVEs
CVE-2025-6208
PYSEC-2026-1560
GHSA-488g-hw5f-x29p
Jul 07, 2026
llama-index-core vulnerable to Uncontrolled Resource Consumption
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 201 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6209
PYSEC-2026-1558
GHSA-2rhq-96q8-4vjq
PYSEC-2025-65
Jul 07, 2026
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A path traversal vulnerability exists in run-llama/llama_index versions 0.11.23 through 0.12.40, specifically within the Affected versions
0.11.23
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
+ 45 more Show less
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-3108
PYSEC-2026-1564
GHSA-m84c-4c34-28gf
PYSEC-2025-249
Jul 07, 2026
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
Incomplete Documentation of Program Execution exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 through v0.12.40. This vulnerability allows remote code execution due to an insecure fallback to Python's pickle module. JsonPickleSerializer prioritizes deserialization using pickle.loads(), which can execute arbitrary code when processing untrusted data. Attackers can exploit this by crafting malicious payloads to achieve full system compromise. The root cause involves the use of an insecure fallback strategy without sufficient input validation or protective safeguards. Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things. Affected versions
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.12.0
0.12.1
0.12.10
+ 53 more Show less
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.38
patch
4 CVEs
CVE-2025-6208
PYSEC-2026-1560
GHSA-488g-hw5f-x29p
Jul 07, 2026
llama-index-core vulnerable to Uncontrolled Resource Consumption
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 201 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6209
PYSEC-2026-1558
GHSA-2rhq-96q8-4vjq
PYSEC-2025-65
Jul 07, 2026
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A path traversal vulnerability exists in run-llama/llama_index versions 0.11.23 through 0.12.40, specifically within the Affected versions
0.11.23
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
+ 45 more Show less
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-3108
PYSEC-2026-1564
GHSA-m84c-4c34-28gf
PYSEC-2025-249
Jul 07, 2026
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
Incomplete Documentation of Program Execution exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 through v0.12.40. This vulnerability allows remote code execution due to an insecure fallback to Python's pickle module. JsonPickleSerializer prioritizes deserialization using pickle.loads(), which can execute arbitrary code when processing untrusted data. Attackers can exploit this by crafting malicious payloads to achieve full system compromise. The root cause involves the use of an insecure fallback strategy without sufficient input validation or protective safeguards. Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things. Affected versions
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.12.0
0.12.1
0.12.10
+ 53 more Show less
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.37
patch
6 CVEs
CVE-2025-6208
PYSEC-2026-1560
GHSA-488g-hw5f-x29p
Jul 07, 2026
llama-index-core vulnerable to Uncontrolled Resource Consumption
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 201 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-5302
PYSEC-2026-1561
GHSA-7753-xrfw-ch36
Jul 07, 2026
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
High
A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38. Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 198 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.4
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.38
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6209
PYSEC-2026-1558
GHSA-2rhq-96q8-4vjq
PYSEC-2025-65
Jul 07, 2026
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A path traversal vulnerability exists in run-llama/llama_index versions 0.11.23 through 0.12.40, specifically within the Affected versions
0.11.23
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
+ 45 more Show less
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-5472
PYSEC-2026-1559
GHSA-3wxx-q3gv-pvvv
PYSEC-2025-251
Jul 07, 2026
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigger a Denial of Service (DoS) by submitting deeply nested JSON structures, leading to a RecursionError and crashing applications. The root cause is the unsafe recursive traversal design and lack of depth validation, which makes the JSONReader susceptible to stack overflow when processing deeply nested JSON. This impacts the availability of services, making them unreliable and disrupting workflows. The issue is resolved in version 0.12.38. Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 198 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.4
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.38
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3108
PYSEC-2026-1564
GHSA-m84c-4c34-28gf
PYSEC-2025-249
Jul 07, 2026
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
Incomplete Documentation of Program Execution exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 through v0.12.40. This vulnerability allows remote code execution due to an insecure fallback to Python's pickle module. JsonPickleSerializer prioritizes deserialization using pickle.loads(), which can execute arbitrary code when processing untrusted data. Attackers can exploit this by crafting malicious payloads to achieve full system compromise. The root cause involves the use of an insecure fallback strategy without sufficient input validation or protective safeguards. Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things. Affected versions
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.12.0
0.12.1
0.12.10
+ 53 more Show less
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.36
patch
6 CVEs
CVE-2025-6208
PYSEC-2026-1560
GHSA-488g-hw5f-x29p
Jul 07, 2026
llama-index-core vulnerable to Uncontrolled Resource Consumption
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 201 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-5302
PYSEC-2026-1561
GHSA-7753-xrfw-ch36
Jul 07, 2026
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
High
A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38. Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 198 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.4
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.38
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6209
PYSEC-2026-1558
GHSA-2rhq-96q8-4vjq
PYSEC-2025-65
Jul 07, 2026
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A path traversal vulnerability exists in run-llama/llama_index versions 0.11.23 through 0.12.40, specifically within the Affected versions
0.11.23
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
+ 45 more Show less
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-5472
PYSEC-2026-1559
GHSA-3wxx-q3gv-pvvv
PYSEC-2025-251
Jul 07, 2026
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigger a Denial of Service (DoS) by submitting deeply nested JSON structures, leading to a RecursionError and crashing applications. The root cause is the unsafe recursive traversal design and lack of depth validation, which makes the JSONReader susceptible to stack overflow when processing deeply nested JSON. This impacts the availability of services, making them unreliable and disrupting workflows. The issue is resolved in version 0.12.38. Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 198 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.4
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.38
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3108
PYSEC-2026-1564
GHSA-m84c-4c34-28gf
PYSEC-2025-249
Jul 07, 2026
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
Incomplete Documentation of Program Execution exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 through v0.12.40. This vulnerability allows remote code execution due to an insecure fallback to Python's pickle module. JsonPickleSerializer prioritizes deserialization using pickle.loads(), which can execute arbitrary code when processing untrusted data. Attackers can exploit this by crafting malicious payloads to achieve full system compromise. The root cause involves the use of an insecure fallback strategy without sufficient input validation or protective safeguards. Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things. Affected versions
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.12.0
0.12.1
0.12.10
+ 53 more Show less
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 13, 2026 · Source: OSV.dev | ||
0.12.35
patch
6 CVEs
CVE-2025-6208
PYSEC-2026-1560
GHSA-488g-hw5f-x29p
Jul 07, 2026
llama-index-core vulnerable to Uncontrolled Resource Consumption
5.3
/ 10
Medium
Network
Low
None
None
Unchanged
None
None
Low
The Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 201 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-7647
PYSEC-2026-1562
GHSA-cr7q-2w66-hjcm
Jul 07, 2026
llama-index-core insecurely handles temporary files
7.3
/ 10
High
Local
Low
Low
None
Unchanged
High
High
Low
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 214 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.41
0.12.42
0.12.43
0.12.44
0.12.45
0.12.46
0.12.47
0.12.48
0.12.49
0.12.5
0.12.50
0.12.51
0.12.52
0.12.52.post1
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.13.0
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-5302
PYSEC-2026-1561
GHSA-7753-xrfw-ch36
Jul 07, 2026
LlamaIndex affected by a Denial of Service (DOS) in JSONReader
8.6
/ 10
High
Network
Low
None
None
Unchanged
Low
Low
High
A denial of service vulnerability exists in the JSONReader component of the run-llama/llama_index repository, specifically in version v0.12.37. The vulnerability is caused by uncontrolled recursion when parsing deeply nested JSON files, which can lead to Python hitting its maximum recursion depth limit. This results in high resource consumption and potential crashes of the Python process. The issue is resolved in version 0.12.38. Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 198 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.4
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.38
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-6209
PYSEC-2026-1558
GHSA-2rhq-96q8-4vjq
PYSEC-2025-65
Jul 07, 2026
LlamaIndex vulnerable to Path Traversal attack through its encode_image function
7.5
/ 10
High
Network
Low
None
None
Unchanged
High
None
None
A path traversal vulnerability exists in run-llama/llama_index versions 0.11.23 through 0.12.40, specifically within the Affected versions
0.11.23
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
+ 45 more Show less
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 07, 2026 · Source: OSV.dev
CVE-2025-5472
PYSEC-2026-1559
GHSA-3wxx-q3gv-pvvv
PYSEC-2025-251
Jul 07, 2026
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
6.5
/ 10
Medium
Network
Low
None
Required
Unchanged
None
None
High
The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigger a Denial of Service (DoS) by submitting deeply nested JSON structures, leading to a RecursionError and crashing applications. The root cause is the unsafe recursive traversal design and lack of depth validation, which makes the JSONReader susceptible to stack overflow when processing deeply nested JSON. This impacts the availability of services, making them unreliable and disrupting workflows. The issue is resolved in version 0.12.38. Affected versions
0.10.0
0.10.1
0.10.10
0.10.11
0.10.11.post1
0.10.12
0.10.13
0.10.14
0.10.14.post1
0.10.15
0.10.16
0.10.16.post1
+ 198 more Show less
0.10.17
0.10.18
0.10.18.post1
0.10.19
0.10.2
0.10.20
0.10.20.post1
0.10.20.post2
0.10.20.post3
0.10.21
0.10.21.post1
0.10.22
0.10.23
0.10.23.post1
0.10.24
0.10.24.post1
0.10.24a1
0.10.25
0.10.25.post1
0.10.25.post2
0.10.25.post3
0.10.25a1
0.10.26
0.10.27
0.10.28
0.10.29
0.10.3
0.10.30
0.10.31
0.10.32
0.10.33
0.10.34
0.10.35
0.10.35.post1
0.10.36
0.10.37
0.10.37.post1
0.10.38
0.10.38.post1
0.10.38.post2
0.10.39
0.10.39.post1
0.10.40
0.10.41
0.10.42
0.10.43
0.10.43.post1
0.10.44
0.10.45
0.10.46
0.10.47
0.10.48
0.10.48.post1
0.10.49
0.10.5
0.10.50
0.10.50.post1
0.10.51
0.10.52
0.10.52.post1
0.10.52.post2
0.10.53
0.10.53.post1
0.10.54
0.10.54.post1
0.10.55
0.10.56
0.10.57
0.10.58
0.10.59
0.10.59a1
0.10.59a2
0.10.5a1
0.10.5a10
0.10.5a2
0.10.5a3
0.10.5a4
0.10.5a5
0.10.5a6
0.10.5a7
0.10.5a8
0.10.5a9
0.10.6
0.10.6.post1
0.10.60
0.10.61
0.10.62
0.10.63
0.10.64
0.10.65
0.10.66
0.10.67
0.10.68
0.10.68.post1
0.10.7
0.10.8
0.10.8.post1
0.10.9
0.11.0
0.11.0.post1
0.11.1
0.11.10
0.11.11
0.11.12
0.11.13
0.11.13.post1
0.11.14
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.2
0.11.20
0.11.21
0.11.22
0.11.23
0.11.3
0.11.4
0.11.5
0.11.6
0.11.7
0.11.8
0.11.9
0.12.0
0.12.1
0.12.10
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.4
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
0.9.41
0.9.42
0.9.42.post3
0.9.43
0.9.44
0.9.44.post1
0.9.44.post2
0.9.44.post3
0.9.45
0.9.46
0.9.47
0.9.48
0.9.49
0.9.50
0.9.50.post1
0.9.51
0.9.52
0.9.53
0.9.54
0.9.55
0.9.56
Fixed in
0.12.38
References
Updated Jul 13, 2026 · Source: OSV.dev
CVE-2025-3108
PYSEC-2026-1564
GHSA-m84c-4c34-28gf
PYSEC-2025-249
Jul 07, 2026
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
5.0
/ 10
Medium
Network
High
None
Required
Unchanged
Low
Low
Low
Incomplete Documentation of Program Execution exists in the run-llama/llama_index library's JsonPickleSerializer component, affecting versions v0.12.27 through v0.12.40. This vulnerability allows remote code execution due to an insecure fallback to Python's pickle module. JsonPickleSerializer prioritizes deserialization using pickle.loads(), which can execute arbitrary code when processing untrusted data. Attackers can exploit this by crafting malicious payloads to achieve full system compromise. The root cause involves the use of an insecure fallback strategy without sufficient input validation or protective safeguards. Version 0.12.41 renames JsonPickleSerializer to PickleSerializer and adds a warning to the docs to only use PickleSerializer to deserialize safe things. Affected versions
0.11.15
0.11.16
0.11.17
0.11.18
0.11.19
0.11.20
0.11.21
0.11.22
0.11.23
0.12.0
0.12.1
0.12.10
+ 53 more Show less
0.12.10.post1
0.12.11
0.12.12
0.12.13
0.12.14
0.12.15
0.12.16
0.12.16.post1
0.12.17
0.12.18
0.12.19
0.12.2
0.12.20
0.12.21
0.12.22
0.12.23
0.12.23.post1
0.12.23.post2
0.12.24
0.12.24.post1
0.12.25
0.12.26
0.12.27
0.12.27a1
0.12.27a2
0.12.27a3
0.12.28
0.12.29
0.12.3
0.12.30
0.12.31
0.12.32
0.12.33
0.12.33.post1
0.12.34
0.12.34.post1
0.12.34a1
0.12.34a2
0.12.34a3
0.12.34a4
0.12.34a5
0.12.35
0.12.36
0.12.37
0.12.38
0.12.39
0.12.4
0.12.40
0.12.5
0.12.6
0.12.7
0.12.8
0.12.9
Fixed in
0.12.41
References
Updated Jul 13, 2026 · Source: OSV.dev |