LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files` argument, which is directly passed into `os.system`. An attacker who controls the content of this argument can inject and execute arbitrary shell commands. This vulnerability can be exploited locally if the attacker has control over the CLI arguments, and remotely if a web application calls the LLama-Index CLI with a user-controlled filename. This issue can lead to arbitrary code execution on the affected system.
Metrics
Affected Vendors & Products
References
History
Thu, 29 May 2025 02:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
References |
| |
Metrics |
threat_severity
|
cvssV3_1
|
Wed, 28 May 2025 14:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 28 May 2025 09:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files` argument, which is directly passed into `os.system`. An attacker who controls the content of this argument can inject and execute arbitrary shell commands. This vulnerability can be exploited locally if the attacker has control over the CLI arguments, and remotely if a web application calls the LLama-Index CLI with a user-controlled filename. This issue can lead to arbitrary code execution on the affected system. | |
Title | Command Injection in LLama-Index CLI in run-llama/llama_index | |
Weaknesses | CWE-78 | |
References |
| |
Metrics |
cvssV3_0
|

Status: PUBLISHED
Assigner: @huntr_ai
Published: 2025-05-28T09:34:10.993Z
Updated: 2025-05-28T13:25:50.026Z
Reserved: 2025-02-27T11:29:11.678Z
Link: CVE-2025-1753

Updated: 2025-05-28T13:25:44.559Z

Status : Awaiting Analysis
Published: 2025-05-28T10:15:21.333
Modified: 2025-05-28T15:01:30.720
Link: CVE-2025-1753
