id: PYSEC-2025-252 published: "2025-07-07T10:15:29.040Z" modified: "2026-07-13T05:49:41.236465Z" aliases: - CVE-2025-6210 details: A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. The vulnerability arises from inadequate handling of hardlinks in the load_data() method, where the security checks fail to differentiate between real files and hardlinks. This issue is resolved in version 0.5.2. affected: - package: name: llama-index ecosystem: PyPI purl: pkg:pypi/llama-index ranges: - type: ECOSYSTEM events: - introduced: "0" - fixed: 0.5.2 versions: - 0.4.10 - 0.4.11 - 0.4.12 - 0.4.13 - 0.4.14 - 0.4.15 - 0.4.16 - 0.4.17 - 0.4.18 - 0.4.19 - 0.4.20 - 0.4.21 - 0.4.22 - 0.4.22.post1 - 0.4.23 - 0.4.24 - 0.4.25 - 0.4.26 - 0.4.27 - 0.4.28 - 0.4.29 - 0.4.30 - 0.4.31 - 0.4.32 - 0.4.33 - 0.4.34 - 0.4.35 - 0.4.35.post1 - 0.4.36 - 0.4.37 - 0.4.38 - 0.4.39 - 0.4.4 - 0.4.4.post1 - 0.4.4.post2 - 0.4.40 - 0.4.5 - 0.4.6 - 0.4.7 - 0.4.8 - 0.4.9 - 0.5.0 - 0.5.1 ecosystem_specific: {} references: - type: FIX url: https://github.com/run-llama/llama_index/commit/a86c96ae0e662492eeb471b658ae849a93f628ff - type: EVIDENCE url: https://huntr.com/bounties/a654b322-a509-4448-a1f5-0f22850b4687 severity: - type: CVSS_V3 score: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N