LlamaIndex is a data-indexing and retrieval framework embedded across applications that integrate large language models with external data sources, presenting a focused but strategically positioned vulnerability surface within the generative AI application stack. Despite a narrow product footprint, the vendor's presence in the top decile of the vulnerability landscape reflects its adoption in production AI systems where improper handling of untrusted inputs carries outsized risk. Vulnerabilities affecting LlamaIndex skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in weakness classes including SQL injection, code injection, path traversal, and improper recursion control—patterns that reflect the vendor's exposure to unvalidated user inputs, dynamic code execution, and filesystem operations in data-retrieval contexts. Defenders should treat LlamaIndex advisories as high-priority for any LLM-integrated system using the framework and apply input-validation and sandboxing controls accordingly; live severity, exploitation, and exposure counts are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Llamaindex over time
Signals from CVEs in this vendor scope (25 CVEs).
25 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2025-1793CRITICAL Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data usin | Jun 5, 2025 | 9.8 | 31 | NO | NO |
CVE-2025-1750CRITICAL An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the | Jun 2, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-12909CRITICAL A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `databa | Mar 20, 2025 | 9.8 | 30 | NO | NO |
CVE-2024-23751CRITICAL LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryE | Jan 22, 2024 | 9.8 | 30 | NO | NO |
CVE-2024-3271CRITICAL A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism, | Apr 16, 2024 | 9.8 | 28 | NO | NO |
CVE-2023-39662CRITICAL An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function. | Aug 15, 2023 | 9.8 | 28 | NO | NO |
CVE-2024-58339HIGH LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. | Jan 12, 2026 | 7.5 | 27 | NO | NO |
CVE-2024-14021HIGH LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed | Jan 12, 2026 | 7.8 | 27 | NO | NO |
CVE-2024-11958CRITICAL A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from | Mar 20, 2025 | 9.8 | 25 | NO | NO |
CVE-2024-4181HIGH A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning | May 16, 2024 | 8.8 | 25 | NO | NO |
Signals from CVEs in this vendor scope (25 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Llamaindex.
Media articles that mention a CVE ID that affects a product developed by Llamaindex — matched by CVE ID, not by vendor name.