CVE-2023-39662General(llamaindex_project / llamaindex)

LOWCVSS 9.8 · CRITICAL

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-74

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • llamaindex

Threat summary

  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 2 signals
  • General: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-19); latest day: 1
  • 2 total mentions across 2 days

Affected systems

Products
llamaindex

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-19: 1Mentions · 2026-07-08: 1Technical Details · 2026-02-19: 1Technical Details · 2026-07-08: 102-1907-08
Signal classification1 categories
General
2100.0%
Full discourse2 posts
  • Harley Lewis Foote@harleyfoote_
    General

    How do you trust a security scanner? Point it at a known answer. On a public, already-patched CVE — CVE-2023-39662, LlamaIndex PandasQueryEngine, a CVSS 9.3 RCE — the scanner flags the exact line and returns BLOCK. That's a test of the detector, not a claim about LlamaIndex today. The method's in the report.

    Post summary

    The tweet references the already‑patched CVE‑2023‑39662, noting its RCE nature, but only uses it as a test case for a security scanner without providing any PoC, exploit, or patch details.

    250320303
    13.8K followersView on X
  • Ayush Rijith@AyushRijith
    General

    @_ar9av @prismor_dev the critical ones include CVE-2025-29927 , CVE-2025-7783 , CVE-2023-50447 , CVE-2025-43859, CVE-2023-39662 , CVE-2024-23751 , CVE-2025-1793 this one has a sql injection vulnerability , CVE-2023-39631 , CVE-2024-3829 , CVE-2023-6730 , CVE-2025-64712 and more..

    Post summary

    The tweet lists numerous CVEs, mentioning only that CVE‑2025‑1793 is a SQL injection vulnerability; it provides no details on exploits, patches, or active use.

    0002079
    6 followersView on X
CPE platform detail1 entries

1 of 1 entries

PartVendorProductVersionTarget SWTarget HW
Appllamaindex_projectllamaindex-python-

Explore more