{"id":"CVE-2024-14021","summary":"LlamaIndex \u003c= 0.11.6 BGEM3Index Unsafe Deserialization","details":"LlamaIndex (run-llama/llama_index) versions up to and including 0.11.6 contain an unsafe deserialization vulnerability in BGEM3Index.load_from_disk() in llama_index/indices/managed/bge_m3/base.py. The function uses pickle.load() to deserialize multi_embed_store.pkl from a user-supplied persist_dir without validation. An attacker who can provide a crafted persist directory containing a malicious pickle file can trigger arbitrary code execution when the victim loads the index from disk.","aliases":["PYSEC-2026-85"],"modified":"2026-08-12T03:51:36.415053308Z","published":"2026-01-12T23:04:43.095Z","database_specific":{"cna_assigner":"VulnCheck","cwe_ids":["CWE-502"],"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14021.json"},"references":[{"type":"WEB","url":"https://www.llamaindex.ai/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/14xxx/CVE-2024-14021.json"},{"type":"ADVISORY","url":"https://github.com/run-llama/llama_index"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-14021"},{"type":"ADVISORY","url":"https://www.vulncheck.com/advisories/llamaindex-bgem3index-unsafe-deserialization"},{"type":"EVIDENCE","url":"https://huntr.com/bounties/ab4ceeb4-aa85-4d1c-aaca-4eda1b71fc12"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/run-llama/llama_index","events":[{"introduced":"0"},{"last_affected":"3c64a1b978c15f9349d5d20644feff50ae0f5849"}],"database_specific":{"cpe":"cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:*","extracted_events":[{"introduced":"0"},{"last_affected":"0.11.6"}],"source":["AFFECTED_FIELD","CPE_RANGE"]}}],"versions":["v0.11.6","v0.11.5","v0.11.4","v0.11.3","v0.11.2","v0.11.1","v0.11.0","v0.10.68","v0.10.67.post1","v0.10.67","v0.10.66","v0.10.63","v0.10.62","v0.10.61","v0.10.60","v0.10.59","v0.10.58","v0.10.57","v0.10.55","v0.10.54","v0.10.53","v0.10.52","v0.10.51","v0.10.50","v0.10.49","v0.10.48.post1","v0.10.48","v0.10.47","v0.10.44","v0.10.43","v0.10.42","v0.10.41","v0.10.40","v0.10.38","v0.10.37","v0.10.35","v0.10.34","v0.10.32","v0.10.31","v0.10.30","v0.10.29","v0.10.28.post1","v0.10.28","v0.10.27","v0.10.26","v0.10.25","v0.10.24","v0.10.23","v0.10.22","v0.10.20","v0.10.19","v0.10.18","v0.10.17","v0.10.16","v0.10.15","v0.10.14","v0.10.13.post1","v0.10.13","v0.10.12","v0.10.11","v0.10.10","v0.10.9","v0.10.8","v0.10.7","v0.10.6","v0.10.5","v0.10.3","v0.10.1","v0.10.0","v0.9.48","v0.9.46","v0.9.45.post1","v0.9.42.post2","v0.9.42.post1","v0.9.42","v0.9.41","v0.9.40","v0.9.39","v0.9.38","v0.9.37","v0.9.36","v0.9.31","v0.9.29","v0.9.28.post2","v0.9.28.post1","v0.9.28","v0.9.26","v0.9.25","v0.9.22","v0.9.17.dev1","v0.9.16.post1","v0.9.15.post2","v0.9.15.post1","v0.9.15","v0.9.14.post3","v0.9.12","v0.9.11.post1","v0.9.10","v0.9.9","v0.9.8.post1","v0.9.8","v0.9.7","v0.9.6.post2","v0.9.6.post1","v0.9.6","v0.9.5","v0.9.3.post1","v0.9.3","v0.9.1","v0.9.0","v0.8.69.post2","v0.8.69.post1","v0.8.69","v0.8.66","v0.8.63.post1","v0.8.53.post1","v0.8.45.post1","v0.8.45","v0.8.43.post1","v0.8.43","v0.8.38","v0.8.29.post1","v0.8.25","v0.8.11.post3","v0.8.11.post2","v0.8.11.post1","v0.8.10","v0.8.7","v0.8.5.post1","v0.8.4","v0.8.3","v0.8.2.post1","v0.8.2","v0.8.1.post1","v0.7.24.post1","v0.7.20","v0.7.19","v0.7.14","v0.7.13","v0.7.12","v0.7.11.post1","v0.7.11","v0.7.10","v0.7.9","v0.6.21","v0.6.3","v0.6.0","v0.6.0.alpha1","v0.4.2","v0.4.1","v0.4.0","v0.3.1"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2024-14021.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"}]}