CVE-2023-39662: llama-index vulnerable to arbitrary code execution
(updated )
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the exec
parameter in PandasQueryEngine function.
References
- github.com/advisories/GHSA-2xxc-73fv-36f7
- github.com/jerryjliu/llama_index
- github.com/jerryjliu/llama_index/issues/7054
- github.com/pypa/advisory-database/tree/main/vulns/llama-index/PYSEC-2023-148.yaml
- github.com/run-llama/llama_index/commit/9f3e50a803f519af9ab62e63d413441c43001d81
- github.com/run-llama/llama_index/commit/aa6726706476e0f957a8d57a5ca89e519e93bad7
- nvd.nist.gov/vuln/detail/CVE-2023-39662
Detect and mitigate CVE-2023-39662 with GitLab Dependency Scanning
Secure your software supply chain by verifying that all open source dependencies used in your projects contain no disclosed vulnerabilities. Learn more about Dependency Scanning →