First published: Tue Aug 15 2023(Updated: )
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
Credit: cve@mitre.org cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
pip/llama-index | <0.9.14 | 0.9.14 |
Llamaindex | <=0.7.13 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39662 is classified as a high severity vulnerability due to its potential to allow remote code execution.
To mitigate CVE-2023-39662, upgrade llama_index to version 0.9.14 or later.
CVE-2023-39662 affects llama_index versions 0.7.13 and earlier.
CVE-2023-39662 allows a remote attacker to execute arbitrary code on the affected systems.
CVE-2023-39662 is present in the PandasQueryEngine function of the llama_index library.