Knowledge base
CodexGuild Knowledge Base

llama-index vulnerable to arbitrary code execution

as of Aug 15, 2023 · applies to llama-index < 0.9.14 · canonical · codexguild.com/kb/ghsa-2xxc-73fv-36f7 · exported 2026-10-11
Canonical as of Aug 15, 2023

llama-index vulnerable to arbitrary code execution

Critical severity. Affects llama-index < 0.9.14. Upgrade to 0.9.14 or later.

CVE-2023-39662 / GHSA-2xxc-73fv-36f7 · severity: critical · CVSS 9.8 · PyPI

Affected

  • llama-index < 0.9.14 → fixed in 0.9.14

Details

An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the exec parameter in PandasQueryEngine function.

Source: GHSA-2xxc-73fv-36f7 — GitHub Advisory Database (CC-BY-4.0).