216.73.216.6

CVE-2025-1753

· Published 28/05/2025 10:15 · Modified 28/05/2025 15:01

Labels: CVE-2025-1753 2025-05-28CVE-2025-1753CWE-78[email protected]

Essential information

Published
28/05/2025 10:15
Modified
28/05/2025 15:01
Author
Creator
CVSS
7.8 HIGH (v3.0)
CISA KEV
No
CWE
CVSS vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CVSS metrics

Description

LLama-Index CLI version v0.12.20 contains an OS command injection vulnerability. The vulnerability arises from the improper handling of the `--files` argument, which is directly passed into `os.system`. An attacker who controls the content of this argument can inject and execute arbitrary shell commands. This vulnerability can be exploited locally if the attacker has control over the CLI arguments, and remotely if a web application calls the LLama-Index CLI with a user-controlled filename. This issue can lead to arbitrary code execution on the affected system.

NVD status

Status
Awaiting Analysis — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
llama-index / cli cpe:2.3:a:llama-index:cli:0.12.20:*:*:*:*:*:*:*

References