Packages you depend on that have known security holes (CVEs).
-
Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
llama-index-core/poetry.lock
A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
-
Serious CVE-2025-68664 langchain-core: LangChain: Arbitrary code execution via serialization injection
llama-index-core/poetry.lock
A package you depend on has a known security hole (CVE-2025-68664). Fix: Update that package to its patched version.
-
Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
llama-index-core/poetry.lock
A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
-
Serious CVE-2025-32434 PyTorch is a Python package that provides tensor computation with stro ...
llama-index-core/poetry.lock
A package you depend on has a known security hole (CVE-2025-32434). Fix: Update that package to its patched version.
-
Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
llama-index-integrations/agent/llama-index-agent-openai/poetry.lock
A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
-
Serious CVE-2024-3098 llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
llama-index-integrations/agent/llama-index-agent-openai/poetry.lock
A package you depend on has a known security hole (CVE-2024-3098). Fix: Update that package to its patched version.
-
Serious CVE-2024-3271 llama-index-core Command Injection vulnerability
llama-index-integrations/agent/llama-index-agent-openai/poetry.lock
A package you depend on has a known security hole (CVE-2024-3271). Fix: Update that package to its patched version.
-
Serious CVE-2024-45201 llama_index: exec call in download/integration.py may lead to code injection
llama-index-integrations/agent/llama-index-agent-openai/poetry.lock
A package you depend on has a known security hole (CVE-2024-45201). Fix: Update that package to its patched version.
-
Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
llama-index-integrations/agent/llama-index-agent-openai/poetry.lock
A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
-
Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
llama-index-integrations/llms/llama-index-llms-friendli/poetry.lock
A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
-
Serious CVE-2024-3098 llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
llama-index-integrations/llms/llama-index-llms-friendli/poetry.lock
A package you depend on has a known security hole (CVE-2024-3098). Fix: Update that package to its patched version.
-
Serious CVE-2024-3271 llama-index-core Command Injection vulnerability
llama-index-integrations/llms/llama-index-llms-friendli/poetry.lock
A package you depend on has a known security hole (CVE-2024-3271). Fix: Update that package to its patched version.
-
Serious CVE-2024-45201 llama_index: exec call in download/integration.py may lead to code injection
llama-index-integrations/llms/llama-index-llms-friendli/poetry.lock
A package you depend on has a known security hole (CVE-2024-45201). Fix: Update that package to its patched version.
-
Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
llama-index-integrations/llms/llama-index-llms-friendli/poetry.lock
A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
-
Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
llama-index-integrations/llms/llama-index-llms-llamafile/poetry.lock
A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
-
Serious CVE-2024-3098 llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
llama-index-integrations/llms/llama-index-llms-llamafile/poetry.lock
A package you depend on has a known security hole (CVE-2024-3098). Fix: Update that package to its patched version.
-
Serious CVE-2024-3271 llama-index-core Command Injection vulnerability
llama-index-integrations/llms/llama-index-llms-llamafile/poetry.lock
A package you depend on has a known security hole (CVE-2024-3271). Fix: Update that package to its patched version.
-
Serious CVE-2024-45201 llama_index: exec call in download/integration.py may lead to code injection
llama-index-integrations/llms/llama-index-llms-llamafile/poetry.lock
A package you depend on has a known security hole (CVE-2024-45201). Fix: Update that package to its patched version.
-
Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
llama-index-integrations/llms/llama-index-llms-llamafile/poetry.lock
A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.
-
Serious CVE-2025-64712 Unstructured has Path Traversal via Malicious MSG Attachment that Allows Arbitrary File Write
llama-index-integrations/readers/llama-index-readers-sec-filings/requirements.txt
A package you depend on has a known security hole (CVE-2025-64712). Fix: Update that package to its patched version.
-
Serious CVE-2025-43859 h11: h11 accepts some malformed Chunked-Encoding bodies
llama-index-integrations/storage/docstore/llama-index-storage-docstore-elasticsearch/poetry.lock
A package you depend on has a known security hole (CVE-2025-43859). Fix: Update that package to its patched version.
-
Serious CVE-2024-3098 llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution
llama-index-integrations/storage/docstore/llama-index-storage-docstore-elasticsearch/poetry.lock
A package you depend on has a known security hole (CVE-2024-3098). Fix: Update that package to its patched version.
-
Serious CVE-2024-3271 llama-index-core Command Injection vulnerability
llama-index-integrations/storage/docstore/llama-index-storage-docstore-elasticsearch/poetry.lock
A package you depend on has a known security hole (CVE-2024-3271). Fix: Update that package to its patched version.
-
Serious CVE-2024-45201 llama_index: exec call in download/integration.py may lead to code injection
llama-index-integrations/storage/docstore/llama-index-storage-docstore-elasticsearch/poetry.lock
A package you depend on has a known security hole (CVE-2024-45201). Fix: Update that package to its patched version.
-
Serious CVE-2025-14009 nltk: Zip Slip Vulnerability in nltk Leading to Code Execution
llama-index-integrations/storage/docstore/llama-index-storage-docstore-elasticsearch/poetry.lock
A package you depend on has a known security hole (CVE-2025-14009). Fix: Update that package to its patched version.