CVE-2024-4181

HIGH

Llamaindex < 0.10.13 - Code Injection

Title source: rule
STIX 2.1

Description

A command injection vulnerability exists in the RunGptLLM class of the llama_index library, version 0.9.47, used by the RunGpt framework from JinaAI to connect to Language Learning Models (LLMs). The vulnerability arises from the improper use of the eval function, allowing a malicious or compromised LLM hosting provider to execute arbitrary commands on the client's machine. This issue was fixed in version 0.10.13. The exploitation of this vulnerability could lead to a hosting provider gaining full control over client machines.

Scores

CVSS v3 8.8
EPSS 0.0162
EPSS Percentile 81.9%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-94
Status published
Products (3)
llamaindex/llamaindex 0.9.47 - 0.10.13
pypi/llama-index 0 - 0.10.13PyPI
pypi/llama-index-llms-rungpt 0 - 0.1.3PyPI
Published May 16, 2024
Tracked Since Feb 18, 2026