GHSA-2xxc-73fv-36f7
Dashboard / Vulnerabilities / GHSA-2xxc-73fv-36f7
GHSA-2xxc-73fv-36f7
Summary: llama-index vulnerable to arbitrary code execution
Details: An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
References: https://nvd.nist.gov/vuln/detail/CVE-2023-39662, https://github.com/jerryjliu/llama_index/issues/7054, https://github.com/run-llama/llama_index/commit/9f3e50a803f519af9ab62e63d413441c43001d81, https://github.com/run-llama/llama_index/commit/aa6726706476e0f957a8d57a5ca89e519e93bad7, https://github.com/jerryjliu/llama_index, https://github.com/pypa/advisory-database/tree/main/vulns/llama-index/PYSEC-2023-148.yaml
Affected packages
Package
Name: llama-index
Purl: pkg:pypi/llama-index
Affected ranges
Type: ECOSYSTEM
Events:
