CVE-2025-7707
HIGHDescription
The llama_index library version 0.12.33 sets the NLTK data directory to a subdirectory of the codebase by default, which is world-writable in multi-user environments. This configuration allows local users to overwrite, delete, or corrupt NLTK data files, leading to potential denial of service, data tampering, or privilege escalation. The vulnerability arises from the use of a shared cache directory instead of a user-specific one, making it susceptible to local data tampering and denial of service.
Is your site exposed to CVE-2025-7707?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
Weakness Type (CWE)
Affected Products
| Vendor | Product |
|---|---|
| llamaindex | llamaindex |
References
Frequently Asked Questions
What is CVE-2025-7707? +
How severe is CVE-2025-7707? +
What products are affected by CVE-2025-7707? +
How do I check if I'm vulnerable to CVE-2025-7707? +
Related Vulnerabilities
Insecure creation of temporary files allows local users on systems with non-default configurations to cause denial of service or set …
The application generates uploaded file names using a weak and predictable method based on the request timestamp. This allows a …
mport is the MidnightBSD Package Manager. mport before 2.7.8 used TMPDIR while extracting package metafiles, including when running as root …
Faktory is a language-agnostic background job server. In versions prior to 1.10.0, the embedded Redis bootstrapper is vulnerable to an …
Flameshot is powerful yet simple to use screenshot software. Prior to 14.0.0, the Open With feature wrote screenshots to a …
Products for macOS enables a user logged on to the system to perform a denial-of-service attack, which could be misused …