HomeLlamaindexCVE-2025-7707

CVE-2025-7707

HIGH
7.8CVSS
Published: 2025-10-13
Updated: 2025-10-21
AI Analysis

Description

The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data tampering, or privilege escalation. The vulnerability arises from the use of a shared cache directory instead of a user-specific one, making it susceptible to local data tampering and denial of service.

CVSS Metrics

Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Attack Vector
local
Complexity
low
Privileges
low
User Action
none
Scope
unchanged
Confidentiality
high
Integrity
high
Availability
high
Weaknesses
CWE-377

Metadata

Primary Vendor
LLAMAINDEX
Published
10/13/2025
Last Modified
10/21/2025
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

llamaindex : llamaindex

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief

CVE-CVE-2025-7707 | HIGH Severity | CVEDatabase.com | CVEDatabase.com