VDB
Sign up
MEDIUM6.2

PYSEC-2026-1567

LlamaIndex vulnerability in its ObsidianReader class can lead to Path Traversal exploit

Quick fix

PYSEC-2026-1567 — llama-index-readers-obsidian: upgrade to the fixed version with the command below.

pip install --upgrade 'llama-index-readers-obsidian>=0.5.2'

Details

A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, before version 0.5.2 (specifically in version 0.12.27 of llama-index), allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. The vulnerability arises from inadequate handling of hardlinks in the load_data() method, where the security checks fail to differentiate between real files and hardlinks. This issue is resolved in llama-index-readers-obsidian version 0.5.2.

Are you affected?

Enter the version of the package you're using.

Affected packages

PyPI/llama-index-readers-obsidian
Introduced in: 0Fixed in: 0.5.2
Fixpip install --upgrade 'llama-index-readers-obsidian>=0.5.2'

References