<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T00:57:28.827479+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2025-13308</id>
    <title>bdu:2025-13308</title>
    <updated>2026-10-03T00:57:28.833560+00:00</updated>
    <content>bdu:2025-13308</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2025-13308"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-253760</id>
    <title>EUVD-2026-253760</title>
    <updated>2026-10-03T00:57:28.833591+00:00</updated>
    <content>EUVD-2026-253760</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-253760"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2025-7647</id>
    <title>fkie_cve-2025-7647</title>
    <updated>2026-10-03T00:57:28.833605+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux systems without proper security controls. This vulnerability allows attackers on multi-user systems to steal proprietary models, poison cached embeddings, or conduct symlink attacks. The issue affects all Linux deployments where multiple users share the same system. The vulnerability is classified under CWE-379, CWE-377, and CWE-367, indicating insecure temporary file creation and potential race conditions.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2025-7647"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-cr7q-2w66-hjcm</id>
    <title>GHSA-cr7q-2w66-hjcm — llama-index-core insecurely handles temporary files</title>
    <updated>2026-10-03T00:57:28.833632+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: llama-index-core</p>
<p>The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux systems without proper security controls. This vulnerability allows attackers on multi-user systems to steal proprietary models, poison cached embeddings, or conduct symlink attacks. The issue affects all Linux deployments where multiple users share the same system. The vulnerability is classified under CWE-379, CWE-377, and CWE-367, indicating insecure temporary file creation and potential race conditions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-cr7q-2w66-hjcm"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/pysec-2026-1562</id>
    <title>PYSEC-2026-1562 — llama-index-core insecurely handles temporary files</title>
    <updated>2026-10-03T00:57:28.833657+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> PyPI: llama-index-core</p>
<p>The llama-index-core package, up to version 0.12.44, contains a vulnerability in the `get_cache_dir()` function where a predictable, hardcoded directory path `/tmp/llama_index` is used on Linux systems without proper security controls. This vulnerability allows attackers on multi-user systems to steal proprietary models, poison cached embeddings, or conduct symlink attacks. The issue affects all Linux deployments where multiple users share the same system. The vulnerability is classified under CWE-379, CWE-377, and CWE-367, indicating insecure temporary file creation and potential race conditions.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/pysec-2026-1562"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/rhsa-2025:18984</id>
    <title>RHSA-2025:18984 — Red Hat Security Advisory: Red Hat Ansible Automation Platform 2.5 Container Release Update</title>
    <updated>2026-10-03T00:57:28.833685+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>langchain-text-splitters: XXE Vulnerability in langchain-text-splitters llama-index-core: Insecure Temporary File Handling in run-llama/llama_index django: Potential SQL injection in QuerySet.annotate(), alias(), aggregate(), and extra() on MySQL and MariaDB1 django: Potential partial directory-traversal via archive.extract()</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/rhsa-2025:18984"/>
  </entry>
</feed>
