Vulnerabilities

ID
Packages
Summary
Published
arrow_upward
Attributes
PYSEC-2026-2606
  • PyPI/llama-index
LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class 13 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1560
  • PyPI/llama-index-core
llama-index-core vulnerable to Uncontrolled Resource Consumption 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1556
  • PyPI/llama-index
llama-index has Insecure Temporary File 07 Jul
  • Fix available
  • Severity - 7.1 (High)
PYSEC-2026-1562
  • PyPI/llama-index-core
llama-index-core insecurely handles temporary files 07 Jul
  • Fix available
  • Severity - 7.3 (High)
PYSEC-2026-1561
  • PyPI/llama-index-core
LlamaIndex affected by a Denial of Service (DOS) in JSONReader 07 Jul
  • Fix available
  • Severity - 8.6 (High)
PYSEC-2026-1566
  • PyPI/llama-index-readers-docugami
LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1558
  • PyPI/llama-index-core
LlamaIndex vulnerable to Path Traversal attack through its encode_image function 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1559
  • PyPI/llama-index-core
LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing 07 Jul
  • Fix available
  • Severity - 6.5 (Medium)
PYSEC-2026-1567
  • PyPI/llama-index-readers-obsidian
LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit 07 Jul
  • Fix available
  • Severity - 6.2 (Medium)
PYSEC-2026-1568
  • PyPI/llama-index-readers-obsidian
LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1570
  • PyPI/llama-index-readers-papers
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1569
  • PyPI/llama-index-readers-papers
LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions 07 Jul
  • Fix available
  • Severity - 5.3 (Medium)
PYSEC-2026-1564
  • PyPI/llama-index-core
LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component 07 Jul
  • Fix available
  • Severity - 5.0 (Medium)
PYSEC-2026-1557
  • PyPI/llama-index-cli
LLama-Index CLI OS command injection vulnerability 07 Jul
  • Fix available
  • Severity - 7.8 (High)
PYSEC-2026-1554
  • PyPI/llama-index
LlamaIndex Vulnerable to Denial of Service (DoS) 07 Jul
  • Fix available
  • Severity - 7.5 (High)
PYSEC-2026-1555
  • PyPI/llama-index
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions 07 Jul
  • Fix available
  • Severity - 7.1 (High)