Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Llamaindex

First CVE: Aug 15, 2023Active for: 3 yearsTotal CVEs: 25
44.0
VTI Score
High

LlamaIndex is a data-indexing and retrieval framework embedded across applications that integrate large language models with external data sources, presenting a focused but strategically positioned vulnerability surface within the generative AI application stack. Despite a narrow product footprint, the vendor's presence in the top decile of the vulnerability landscape reflects its adoption in production AI systems where improper handling of untrusted inputs carries outsized risk. Vulnerabilities affecting LlamaIndex skew toward serious outcomes, with an elevated share reaching critical severity, and concentrate in weakness classes including SQL injection, code injection, path traversal, and improper recursion control—patterns that reflect the vendor's exposure to unvalidated user inputs, dynamic code execution, and filesystem operations in data-retrieval contexts. Defenders should treat LlamaIndex advisories as high-priority for any LLM-integrated system using the framework and apply input-validation and sandboxing controls accordingly; live severity, exploitation, and exposure counts are shown alongside this summary.

FAUCET AI Generated
25
Total CVEs
More Total CVEs than 97% of tracked vendors
6.3
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 99% of tracked vendors
8.0
Avg CVSS Score
Higher Avg CVSS Score than 77% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Llamaindex over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 15, 2023
2 years ago
Most Recent CVE
Jan 12, 2026
194 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (25 CVEs).

25 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2025-1793CRITICAL
Multiple vector store integrations in run-llama/llama_index version v0.12.21 have SQL injection vulnerabilities. These vulnerabilities allow an attacker to read and write data usin
Jun 5, 20259.831NONO
CVE-2025-1750CRITICAL
An SQL injection vulnerability exists in the delete function of DuckDBVectorStore in run-llama/llama_index version v0.12.19. This vulnerability allows an attacker to manipulate the
Jun 2, 20259.830NONO
CVE-2024-12909CRITICAL
A vulnerability in the FinanceChatLlamaPack of the run-llama/llama_index repository, versions up to v0.12.3, allows for SQL injection in the `run_sql_query` function of the `databa
Mar 20, 20259.830NONO
CVE-2024-23751CRITICAL
LlamaIndex (aka llama_index) through 0.9.34 allows SQL injection via the Text-to-SQL feature in NLSQLTableQueryEngine, SQLTableRetrieverQueryEngine, NLSQLRetriever, RetrieverQueryE
Jan 22, 20249.830NONO
CVE-2024-3271CRITICAL
A command injection vulnerability exists in the run-llama/llama_index repository, specifically within the safe_eval function. Attackers can bypass the intended security mechanism,
Apr 16, 20249.828NONO
CVE-2023-39662CRITICAL
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
Aug 15, 20239.828NONO
CVE-2024-58339HIGH
LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation.
Jan 12, 20267.527NONO
CVE-2024-14021HIGH
LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed
Jan 12, 20267.827NONO
CVE-2024-11958CRITICAL
A SQL injection vulnerability exists in the `duckdb_retriever` component of the run-llama/llama_index repository, specifically in the latest version. The vulnerability arises from
Mar 20, 20259.825NONO
CVE-2024-4181HIGH
A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning
May 16, 20248.825NONO
View all 25 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products25 CVEs
20%
52%
28%
Severity distribution among all CVEs352,427 CVEs
45%
40%
11%
MediumHighCritical
Attack Vector
Local4 (16.0%)
Network21 (84.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low23 (92.0%)
High2 (8.0%)
Unknown0 (0.0%)
User Interaction
None20 (80.0%)
Unknown0 (0.0%)
Required5 (20.0%)
Privileges Required
Low3 (12.0%)
High0 (0.0%)
None22 (88.0%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (25 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Llamaindex.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Llamaindex — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Llamaindex's Products

View all 3 CNAs →

Top CWEs