Description
A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines.
Analysis and contextual insights are available on OpenCVE Cloud.
Remediation
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
Advisories
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-1728 | A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines. |
Github GHSA |
GHSA-pw38-xv9x-h8ch | RunGptLLM class in LlamaIndex has a command injection |
References
History
Tue, 21 Oct 2025 11:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Llamaindex
Llamaindex llamaindex |
|
| CPEs | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Llamaindex
Llamaindex llamaindex |
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2024-08-01T20:33:52.659Z
Reserved: 2024-04-25T13:52:02.986Z
Link: CVE-2024-4181
Updated: 2024-08-01T20:33:52.659Z
Status : Analyzed
Published: 2024-05-16T09:15:15.553
Modified: 2025-10-21T11:36:16.007
Link: CVE-2024-4181
No data.
OpenCVE Enrichment
No data.
Weaknesses
EUVD
Github GHSA