Bounties
Partners
Community
Info
run-llama / llama_index
Project repository
LlamaIndex is a data framework for your LLM applications
Submit a report
FIRST INTERACTION
WITHIN
14 DAYS
REVIEW
WITHIN
14 DAYS
FIX
WITHIN
N/A DAYS
Arbitrary code execution via unsafe pickle.load in txtai and bge-m3 integrations
Apr 26th 2026
bersechub
•
self closed
Sandbox escape to arbitrary code execution via operator.attrgetter in EvaporateE...
Apr 26th 2026
bersechub
•
self closed
SSRF in ChatGPTPluginToolSpec and OpenAPIToolSpec via Unvalidated URLs
Apr 25th 2026
jd-admrl-ai
•
self closed
SQL Injection in PostgresChatStore via Unsanitized schema_name Parameter
Apr 25th 2026
jd-admrl-ai
•
self closed
SQL injection via f-string interpolation in DB2 vector store delete(), query(),...
Apr 12th 2026
snakeyworm
•
duplicate
None
Sandbox escape in Evaporate extractor via operator.attrgetter bypassing AST dund...
Apr 12th 2026
snakeyworm
•
duplicate
Critical
NoSQL injection via f-string interpolation in Azure Cosmos DB NoSQL vector store...
Apr 12th 2026
snakeyworm
•
duplicate
Critical
Complete Sandbox Escape in EvaporateExtractor via operator.attrgetter Dunder Byp...
Apr 11th 2026
skillwager
•
duplicate
Critical
LLM-Generated SQL Executed Without Sanitization in NLSQLRetriever (Text-to-SQL)
Apr 30th 2026
gauravbhatia1211
•
duplicate
High
Sandbox Escape via operator.attrgetter in Evaporate Extractor — Arbitrary Code E...
Apr 11th 2026
sam8k
•
duplicate
Critical
Sandbox Escape in EvaporateExtractor via operator.attrgetter Bypassing AST Dunde...
Apr 11th 2026
py4y6
•
duplicate
Critical
Sandbox escape RCE via operator.attrgetter in EvaporateExtractor
Apr 12th 2026
ryan-fanpierlabs-security-finder
•
duplicate
Critical
Sandbox escape in Evaporate extractor via operator.attrgetter bypassing AST dund...
Apr 11th 2026
wormysnake
•
duplicate
Critical
Sandbox Escape via operator.attrgetter in Evaporate LLM Code Execution
Apr 11th 2026
lihfdgjr
•
duplicate
High
Indirect prompt injection enables arbitrary SQL execution in NLSQLTableQueryEngi...
Apr 30th 2026
n1neman
•
duplicate
None
SSRF via unvalidated image URL fetching in core schema classes
Mar 29th 2026
pulkit7070
•
duplicate
High
Sandbox Escape via Shallow AST Import Check in PandasQueryEngine exec_utils.py
Mar 29th 2026
hacnho
•
duplicate
High
SSRF via unvalidated image_url in multi-modal LLM generic_utils and schema
Mar 29th 2026
tranhoangtu-it
•
duplicate
Critical
Unauthenticated RCE via Path Traversal in download_dataset_and_source_files
Mar 27th 2026
jdp-security
•
not applicable
SQL Injection via LLM-Generated Queries in Text-to-SQL Pipeline
Apr 30th 2026
tkenaz
•
duplicate
Critical
Arbitrary Code Execution (RCE) via Sandbox Bypass in LlamaIndex (PandasQueryEngi...
Mar 26th 2026
catalyzer9867
•
duplicate
Critical
Supply Chain RCE via Unsanitized pip install in download_integration()
Mar 26th 2026
jdhart81
•
duplicate
Critical
SSRF in llama_index: ImageNode.resolve_image() and 5 other code paths fetch arbi...
Mar 26th 2026
caoxuyang
•
duplicate
High
SQL Injection in llama-index-vector-stores-db2 via delete(), query filters, and...
Apr 12th 2026
romain-deperne
•
duplicate
Critical
Incomplete Fix for CVE-2025-1793: SQL Injection via ref_doc_id in DB2 Vector Sto...
Apr 12th 2026
th3-j0k3r
•
duplicate
Critical
SSRF via Unvalidated Image URLs in Multi-Modal Document Schema and LLM Utils
Mar 26th 2026
nhomyk
•
duplicate
High
SQL Injection in llama-index-vector-stores-db2 and llama-index-vector-stores-cou...
Mar 19th 2026
ar03
•
duplicate
Critical
Arbitrary code execution via unsanitized llama_hub_url in download_llama_module(...
Mar 19th 2026
rishavkumarthapa01-sketch
•
duplicate
High
Sandbox Escape via Nested Import Bypass and Missing __builtins__ Restriction in...
Mar 17th 2026
phenggeler
•
duplicate
None
Arbitrary Code Execution via Pickle Deserialization in EmbeddedTablesUnstructure...
Mar 17th 2026
manja316
•
duplicate
Critical
SQL Injection via unsanitized db_schema in SQLAlchemyChatStore — DDL injection o...
Apr 14th 2026
mscgo
•
duplicate
None
Unsafe pickle.load() in BGEM3Index.load_from_disk() Enables RCE via Malicious In...
Mar 18th 2026
odysseypro25-project
•
self closed
Sandbox escape in EvaporateExtractor via operator.attrgetter bypasses AST dunder...
Apr 12th 2026
eistee82
•
duplicate
Critical
Unsafe pickle deserialization in EmbeddedTablesUnstructuredRetrieverPack leads t...
Mar 17th 2026
narrator3333-hash
•
duplicate
Critical
Sandbox Escape via operator.attrgetter Bypasses AST Validation in EvaporateExtra...
Apr 11th 2026
elucidator-hky
•
duplicate
High
SQL Injection via Unparameterized f-string Query Construction in Multiple Vector...
Mar 19th 2026
elucidator-hky
•
duplicate
High
Server-Side Request Forgery (SSRF) in Core Schema and Multiple Web Readers Due t...
Mar 16th 2026
elucidator-hky
•
self closed
Arbitrary code execution via unsafe pickle.load() and torch.load() in multiple L...
Mar 16th 2026
elucidator-hky
•
self closed
SQL injection in DuckDB vector store via f-string interpolation in DELETE and SE...
Apr 30th 2026
odysseypro25-project
•
not applicable
Arbitrary SQL Execution via NL2SQL LLM Output
Apr 30th 2026
odysseypro25-project
•
not applicable
SQL Injection via db_schema Parameter in SQLAlchemyChatStore
Apr 14th 2026
odysseypro25-project
•
duplicate
High
SimpleDirectoryReader Symlink Traversal → Arbitrary File Read
Apr 27th 2026
rhyk7
•
informative
Medium
Sandbox Escape - RCE in llama-index-program-evaporate
Apr 11th 2026
richorama
•
duplicate
Critical
LlamaIndex: exec() Code Execution with Bypassable Sandbox in Evaporate Extractor
Mar 9th 2026
iamveene
•
self closed
LlamaIndex: SSRF via SimpleWebPageReader -- No URL Validation or Private IP Bloc...
Mar 9th 2026
iamveene
•
self closed
LlamaIndex: RAG Indirect Prompt Injection via Unsanitized Document Context Inser...
Mar 9th 2026
iamveene
•
self closed
LlamaIndex: Supply Chain RCE via download_llama_module Without Integrity Verific...
Mar 26th 2026
iamveene
•
duplicate
High
LlamaIndex: Dynamic Import from Serialized Ray Pipeline Config Leading to Arbitr...
Apr 27th 2026
iamveene
•
not applicable
SQL++ Injection in CouchbaseQueryVectorStore via unsanitized MetadataFilter keys...
Apr 27th 2026
richorama
•
informative
Critical
World-readable persist() artifacts expose sensitive data
Apr 27th 2026
amadhan882
•
not applicable
Unprotected pickle.load() in 5 Locations Across 4 LlamaIndex Integration Package...
Mar 9th 2026
iamveene
•
self closed
NoSQL Injection via F-String Interpolation in Azure Cosmos DB Vector Store
Apr 12th 2026
iamveene
•
duplicate
High
Root RCE Patch Bypass in LlamaIndex v0.14.15 via Persistent Insecure Deserializa...
Apr 27th 2026
amadhan882
•
not applicable
ReDoS via User-Supplied Regex in SEC Filings FastAPI Endpoint
Apr 24th 2026
abhiabhi2306
•
informative
Medium
Sandbox escape in exec_utils allows arbitrary command execution
Mar 8th 2026
vnykmshr
•
duplicate
Critical
External Control of File Name or Path in llamaindex-cli new-package allows direc...
Apr 24th 2026
cardosource
•
not applicable
Unsafe deserialization via pickle in LlamaIndex storage and index persistence
Apr 24th 2026
etwithin
•
spam
Sandbox Bypass in safe_exec / safe_eval leading to Remote Code Execution (RCE) v...
Mar 7th 2026
amitzalman
•
duplicate
Critical
Sandbox Escape via AST Bypass and __builtins__ Injection in safe_exec leads to R...
Mar 6th 2026
sendorrr
•
self closed
SQL Injection via MetadataFilter key/value in 7 Vector Store query() Paths (Mari...
Mar 5th 2026
d3banjan
•
self closed
NoSQL Injection in AzureCosmosDBNoSqlVectorSearch `delete()` and `_query()` Meth...
Mar 6th 2026
hiyokosauna37
•
self closed
SQL Injection in PGVectorStore metadata filtering via `_build_filter_clause()`
Apr 24th 2026
directbuilds
•
informative
Critical
EdgeQL Injection in LlamaIndex Gel VectorStore — Cross-Table Data Exfiltration a...
Apr 23rd 2026
apeiria-zero
•
informative
High
Sandbox Escape in Evaporate Extractor via chr()+operator.attrgetter — Remote Cod...
Mar 5th 2026
apeiria-zero
•
duplicate
Critical
AST Sandbox Bypass via eval/exec string literals in _validate_generated_code() l...
Mar 4th 2026
erc840902
•
duplicate
Critical
API Key Leak via Incomplete Callback Filtering in LLM Callback Decorators
Apr 14th 2026
2201029-cyber
•
duplicate
Medium
Unsafe pickle.load() in SimpleObjectNodeMapping.from_persist_dir() enables arbit...
Mar 3rd 2026
sinhsinhan
•
duplicate
Critical
LlamaIndex SSRF via Unvalidated Image URL Fetching in LanceDB Integration - Acce...
Mar 3rd 2026
avienma007
•
duplicate
Critical
Arbitrary Code Execution via Code Interpreter Tool Without Sandboxing
Apr 21st 2026
avienma007
•
informative
Critical
Show more...
CRITICAL
$1500
HIGH
$750
MEDIUM
$125
LOW
$20