Miggo Logo

CVE-2025-7707: llama-index has Insecure Temporary File

7.1

CVSS Score
3.0

Basic Information

EPSS Score
-
Published
10/13/2025
Updated
10/13/2025
KEV Status
No
Technology
TechnologyPython

Technical Details

CVSS Vector
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:H
Package NameEcosystemVulnerable VersionsFirst Patched Version
llama-indexpip< 0.13.00.13.0

Vulnerability Intelligence
Miggo AIMiggo AI

Miggo AIRoot Cause Analysis:
In progress

WAF Protection Rules

WAF Rule

T** ll*m*_in**x li*r*ry v*rsion *.**.** s*ts t** NLTK **t* *ir**tory to * su**ir**tory o* t** *o****s* *y ****ult, w*i** is worl*-writ**l* in multi-us*r *nvironm*nts. T*is *on*i*ur*tion *llows lo**l us*rs to ov*rwrit*, **l*t*, or *orrupt NLTK **t* *i

Reasoning

No *n*lysis *v*il**l*