OSS Support Hub / Machine Learning

Python Machine Learning MIT Latest: v0.14.23

LlamaIndex

Data framework for building LLM applications over custom data sources

Project Health at a Glance

Live data from GitHub and PyPI, updated daily.

50.5K+696
GitHub Stars
📦
v0.14.23
Latest Release · 5 days ago
🔄
17d
Avg. Release Cadence
🐛
525
Open Issues
📅
3 days ago
Last Commit
🔒
10
Active CVEs

Data last fetched: 2026-06-29

Known Vulnerabilities

10 active CVEs reported via OSV.dev

SQL injection in llama-index

Published: 2024-01-22 No fix available

llama-index vulnerable to arbitrary code execution

Published: 2023-08-15 Fixed in: 0.9.14

LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

Published: 2025-07-10 Fixed in: 0.12.41

LlamaIndex Vulnerable to Denial of Service (DoS)

Published: 2025-05-10 Fixed in: 0.12.21

LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions

Published: 2025-03-20 Fixed in: 0.12.3

LlamaIndex Uncontrolled Resource Consumption vulnerability

Published: 2025-03-20 Fixed in: 0.12.9

RunGptLLM class in LlamaIndex has a command injection

Published: 2024-05-16 Fixed in: 0.10.13

llama-index has Insecure Temporary File

Published: 2025-10-13 Fixed in: 0.13.0

llama_index vulnerable to SQL Injection

Published: 2025-06-05 Fixed in: 0.12.28
PYSEC-2023-148 CVSS_V3

Published: 2023-08-15 Fixed in: 0.7.14

Alternatives to LlamaIndex

Other Machine Learning projects in the Python ecosystem worth evaluating.

Support Options for LlamaIndex

Enterprise Support via DepKeep

Get SLA-backed support, security patches, and direct access to senior engineers for LlamaIndex — without relying on volunteer maintainers.