Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
Github GHSA |
GHSA-fxc2-8m62-m85x | LlamaIndex includes an exec call for `import {cls_name}` |
Mon, 25 Nov 2024 19:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Llamaindex
Llamaindex llamaindex |
|
| CPEs | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Llamaindex
Llamaindex llamaindex |
|
| Metrics |
ssvc
|
ssvc
|
Fri, 23 Aug 2024 01:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Title | llama_index: exec call in download/integration.py may lead to code injection | |
| Weaknesses | CWE-94 | |
| References |
| |
| Metrics |
threat_severity
|
cvssV3_1
|
Thu, 22 Aug 2024 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Thu, 22 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An issue was discovered in llama_index before 0.10.38. download/integration.py includes an exec call for import {cls_name}. | |
| References |
|
Status: PUBLISHED
Assigner: mitre
Published:
Updated: 2024-11-25T18:19:38.593Z
Reserved: 2024-08-22T00:00:00.000Z
Link: CVE-2024-45201
Updated: 2024-08-22T20:30:12.394Z
Status : Analyzed
Published: 2024-08-22T20:15:10.063
Modified: 2025-10-21T18:59:17.453
Link: CVE-2024-45201
OpenCVE Enrichment
No data.
Github GHSA