Get real-time updates on Telegram
CVE-2025-7707: llamaindex from 0.12.33 (inclusive), before 0.13.0 (exclusive); +1 more affected products
CVE-2025-7707. CVSS 3.1 base score 7.8 (HIGH, NVD). EPSS 0.00186 (percentile 0.07487), scored 2026-10-06.
Affected technology
llamaindex · from 0.12.33 (inclusive), before 0.13.0 (exclusive)
llamaindex
run-llama/llama_index · unspecified to before v0.13.0
run-llama
Description’s affected range: version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default
Component: Not specified by the source
Attack conditions (NVD, CVSS 3.1): Local · Low privileges required · No user interaction required
What an attacker can do
Local users can overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data tampering, or privilege escalation. NVD’s CVSS 3.1 assessment (base score 7.8/10) rates confidentiality, integrity and availability impact as high.
- CWE
- CWE-377
- CCR priority
- 31.2 /100 (P4)
- CVSS 3.1
- 7.8 /10 · CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H · NVD
- EPSS
- 0.00186 · percentile 0.07522 · 2026-10-08
- KEV
- no
Provenance
- FIRST EPSS daily exploit-probability · Source record · observed 2026-10-08 17:36:22.845483+00:00 UTC
- NVD CVE API 2.0 · Source record · observed 2026-10-08 17:32:11.049884+00:00 UTC
Stable permalink: https://cybercodered.org/item/cve-cve-2025-7707.html