CodexGuild Knowledge Base
llama-index vulnerable to arbitrary code execution
Canonical as of Aug 15, 2023
llama-index vulnerable to arbitrary code execution
Critical severity. Affects llama-index < 0.9.14. Upgrade to 0.9.14 or later.
CVE-2023-39662 / GHSA-2xxc-73fv-36f7 · severity: critical · CVSS 9.8 · PyPI
Affected
llama-index< 0.9.14 → fixed in 0.9.14
Details
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the exec parameter in PandasQueryEngine function.
Source: GHSA-2xxc-73fv-36f7 — GitHub Advisory Database (CC-BY-4.0).