PT-2025-27525 · Unknown · Llama Index

Astrabert

·

Published

2025-07-01

·

Updated

2025-07-14

·

CVE-2025-6210

CVSS v3.1

6.2

Medium

VectorAV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions: llama index version 0.12.27
Description: A flaw in the ObsidianReader class allows for hardlink-based path traversal, enabling attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. This issue arises from inadequate handling of hardlinks in the load data() method.
Recommendations: For version 0.12.27, update to version 0.5.2 to resolve the issue. As a temporary workaround, consider restricting access to sensitive system files to minimize the risk of exploitation.

Exploit

Fix

Path traversal

Weakness Enumeration

Related Identifiers

CVE-2025-6210
GHSA-3J8R-JF9W-5CMH

Affected Products

Llama Index