Bounties
Partners
Community
Info
run-llama / llama_index
Project repository
LlamaIndex is a data framework for your LLM applications
Submit a report
FIRST INTERACTION
WITHIN
5 DAYS
REVIEW
WITHIN
5 DAYS
FIX
WITHIN
N/A DAYS
SQL++/N1QL Injection in CouchbaseQueryVectorStore.query() metadata filters (llam...
May 22nd 2026
wernerina
•
self closed
SQL++/N1QL Injection in CouchbaseQueryVectorStore.query() metadata filters (llam...
May 22nd 2026
wernerina
•
self closed
SQL++/N1QL Injection in CouchbaseQueryVectorStore.query() metadata filters (llam...
May 22nd 2026
wernerina
•
self closed
SQL++/N1QL Injection in CouchbaseQueryVectorStore.query() metadata filters (llam...
May 22nd 2026
wernerina
•
self closed
SQL++/N1QL Injection in CouchbaseQueryVectorStore.query() metadata filters (llam...
May 22nd 2026
wernerina
•
self closed
SQL++/N1QL Injection in CouchbaseQueryVectorStore.query() metadata filters (llam...
May 22nd 2026
wernerina
•
self closed
SQL++/N1QL Injection in CouchbaseQueryVectorStore.query() metadata filters (llam...
May 22nd 2026
wernerina
•
self closed
Server-Side Request Forgery (SSRF) via ImageNode.resolve_image() and ImageDocume...
May 22nd 2026
galanzi2580-wq
•
self closed
PickleSerializer in Workflow Context Enables Arbitrary Code Execution via pickle...
May 22nd 2026
galanzi2580-wq
•
self closed
Arbitrary local file read via SimpleDirectoryReader.load_resource() path travers...
May 22nd 2026
galanzi2580-wq
•
self closed
Unsafe pickle deserialization via torch.load() in llama-index-embeddings-adapt...
May 17th 2026
k4lif1
•
self closed
llama-index-evaporate: exec() sandbox escape via operator.attrgetter RCE
May 12th 2026
ssjcorpsec
•
self closed
llama-index-evaporate: exec() sandbox escape via operator.attrgetter RCE
May 12th 2026
ssjcorpsec
•
self closed
llama-index-evaporate: exec() sandbox escape via operator.attrgetter RCE
May 12th 2026
ssjcorpsec
•
self closed
SSRF via resolve_image — requests.get on user-controlled image_url in llama_inde...
May 10th 2026
muraveyapp
•
duplicate
None
SSRF via resolve_image — requests.get on user-controlled image_url in llama_inde...
May 10th 2026
muraveyapp
•
duplicate
None
SSRF via resolve_image — requests.get on user-controlled image_url in llama_inde...
May 10th 2026
muraveyapp
•
duplicate
None
Critical SSRF to Cloud Metadata Exfiltration via Unvalidated URL Fetching in Web...
May 10th 2026
iffi-crux
•
duplicate
Critical
CVE-2025-1793: Incomplete Scope — Five Additional Vector Store Integrations with...
May 8th 2026
rui-wang-8
•
duplicate
Critical
Critical RCE via Chained Arbitrary File Write and Insecure Deserialization in Tx...
May 8th 2026
uchalm
•
duplicate
Critical
Unsafe pickle deserialization in TxtaiVectorStore.from_persist_path fallback con...
May 8th 2026
am-statementforge
•
duplicate
High
SQL Injection in llama-index-vector-stores-db2
May 8th 2026
pwilkin
•
duplicate
High
Stack-overflow DoS via 4 unguarded recursive walkers in llama-index-core
May 14th 2026
linziyuu
•
informative
High
Sandbox escape via operator.attrgetter in llama-index-program-evaporate
May 11th 2026
nisartest20-bit
•
informative
Critical
Arbitrary code execution via unsafe pickle.load in txtai and bge-m3 integrations
Apr 26th 2026
bersechub
•
self closed
Sandbox escape to arbitrary code execution via operator.attrgetter in EvaporateE...
Apr 26th 2026
bersechub
•
self closed
SSRF in ChatGPTPluginToolSpec and OpenAPIToolSpec via Unvalidated URLs
Apr 25th 2026
jd-admrl-ai
•
self closed
SQL Injection in PostgresChatStore via Unsanitized schema_name Parameter
Apr 25th 2026
jd-admrl-ai
•
self closed
SSRF via resolve_binary() and ImageDocument/ImageNode.image_url allows cloud met...
May 10th 2026
elibell004
•
duplicate
High
SQL injection via f-string interpolation in DB2 vector store delete(), query(),...
Apr 12th 2026
snakeyworm
•
duplicate
None
Sandbox escape in Evaporate extractor via operator.attrgetter bypassing AST dund...
Apr 12th 2026
snakeyworm
•
duplicate
Critical
NoSQL injection via f-string interpolation in Azure Cosmos DB NoSQL vector store...
Apr 12th 2026
snakeyworm
•
duplicate
Critical
Complete Sandbox Escape in EvaporateExtractor via operator.attrgetter Dunder Byp...
Apr 11th 2026
skillwager
•
duplicate
Critical
LLM-Generated SQL Executed Without Sanitization in NLSQLRetriever (Text-to-SQL)
Apr 30th 2026
gauravbhatia1211
•
duplicate
High
Sandbox Escape via operator.attrgetter in Evaporate Extractor — Arbitrary Code E...
Apr 11th 2026
sam8k
•
duplicate
Critical
Sandbox Escape in EvaporateExtractor via operator.attrgetter Bypassing AST Dunde...
Apr 11th 2026
py4y6
•
duplicate
Critical
SQL/NoSQL Injection in multiple vector store integrations via unsanitized ref_do...
May 8th 2026
py4y6
•
duplicate
High
SQL Injection in llama-index-vector-stores-db2 DB2LlamaVS.delete() — same f-stri...
May 8th 2026
sovnodeai
•
duplicate
Critical
Systemic SSRF in llama-index-core: unvalidated `requests.get()` on user-controll...
May 10th 2026
lolbotym
•
duplicate
High
Show more...
CRITICAL
$1500
HIGH
$750
MEDIUM
$125
LOW
$20