CVE-2025-7647
The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux systems without proper security controls. This vulnerability allows attackers on multi-user systems to steal proprietary models, poison cached embeddings, or conduct symlink attacks. The issue affects all Linux deployments where multiple users share the same system. The vulnerability is classified under CWE-379, CWE-377, and CWE-367, indicating insecure temporary file creation and potential race conditions.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.3
- CVSS vector
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:L
- EPSS probability
- 0.15%
- CWE
- CWE-378
- Published
- 2025-09-27
- Last modified
- 2026-03-12
Affected products
- run-llama run-llama/llama_index
Weakness type
Related vulnerabilities
- CVE-2026-46388 — osquery: Unprivileged users can temporarily read file carve contents
- CVE-2026-4137 — Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlflow
- CVE-2026-33572 — OpenClaw < 2026.2.17 - Insufficient File Permissions in Session Transcript Files
- CVE-2026-4822 — Enter Software Iperius Backup Backup Service temp file
- CVE-2026-2817 — Spring Data Geode Insecure Temporary Directory Usage
- CVE-2025-46685 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File...
- CVE-2025-46684 — Dell SupportAssist OS Recovery, versions prior to 5.5.15.1, contain a Creation of Temporary File...
- CVE-2025-34352 — JumpCloud Remote Assist < 0.317.0 Arbitrary File Write/Delete via Insecure Temp Directory