PT-2025-27525 · Unknown · Llama Index
Astrabert
·
Published
2025-07-01
·
Updated
2025-07-14
·
CVE-2025-6210
CVSS v3.1
6.2
Medium
| Vector | AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions:
llama index version 0.12.27
Description:
A flaw in the ObsidianReader class allows for hardlink-based path traversal, enabling attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. This issue arises from inadequate handling of hardlinks in the
load data() method.Recommendations:
For version 0.12.27, update to version 0.5.2 to resolve the issue. As a temporary workaround, consider restricting access to sensitive system files to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Llama Index