CRITICAL9.8
PYSEC-2023-148
Quick fix
PYSEC-2023-148 — llama-index: upgrade to the fixed version with the command below.
pip install --upgrade 'llama-index>=0.7.14'Details
An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.
Are you affected?
Enter the version of the package you're using.