Metrics
Affected Vendors & Products
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20216 | LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class |
Github GHSA |
GHSA-fmrf-6jv9-qjc7 | LlamaIndex is vulnerable to Path Traversal attack through its ObsidianReader class |
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Wed, 30 Jul 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Llamaindex
Llamaindex llamaindex |
|
| CPEs | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Llamaindex
Llamaindex llamaindex |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 07 Jul 2025 14:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Jul 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within the intended directory. This flaw enables attackers to place symlinks pointing to files outside the vault directory, which are then processed as valid Markdown files, potentially exposing sensitive information. | |
| Title | Path Traversal via Symbolic Links in run-llama/llama_index | |
| Weaknesses | CWE-22 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-07-07T14:00:59.560Z
Reserved: 2025-03-31T12:36:26.873Z
Link: CVE-2025-3046
Updated: 2025-07-07T14:00:47.025Z
Status : Analyzed
Published: 2025-07-07T10:15:26.900
Modified: 2025-07-30T21:25:03.810
Link: CVE-2025-3046
OpenCVE Enrichment
No data.
EUVD
Github GHSA