<?xml version="1.0" encoding="utf-8" standalone="yes"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>LlamaIndex on GMO Flatt Security Research</title>
    <link>https://flatt.tech/research/tags/llamaindex/</link>
    <description>Recent content in LlamaIndex on GMO Flatt Security Research</description>
    <generator>Hugo</generator>
    <language>en</language>
    <lastBuildDate>Wed, 29 Oct 2025 00:00:00 +0000</lastBuildDate>
    <atom:link href="https://flatt.tech/research/tags/llamaindex/index.xml" rel="self" type="application/rss+xml" />
    <item>
      <title>Security Risks of LLM Frameworks with Case Studies</title>
      <link>https://flatt.tech/research/posts/llm-framework-vulns-exposed/</link>
      <pubDate>Wed, 29 Oct 2025 00:00:00 +0000</pubDate>
      <guid>https://flatt.tech/research/posts/llm-framework-vulns-exposed/</guid>
      <description>&lt;h2 id=&#34;introduction&#34;&gt;Introduction&lt;/h2&gt;&#xA;&lt;p&gt;Hello. I’m Mori (&lt;a href=&#34;https://twitter.com/ei01241&#34; target=&#34;_blank&#34; rel=&#34;noopener&#34;&gt;@ei01241&lt;/a&gt;&#xA;), a security engineer at GMO Flatt Security, Inc.&lt;/p&gt;&#xA;&lt;p&gt;In recent years, the evolution of Large Language Models (LLMs) has accelerated the development of a wide range of AI applications, such as chatbots, data analysis/summarization, and autonomous agents. &lt;strong&gt;LLM frameworks&lt;/strong&gt; like LangChain and LlamaIndex abstract LLM collaboration and external data connections to improve development efficiency, but behind this convenience lie new security risks.&lt;/p&gt;&#xA;&lt;p&gt;In this article, we will explain common vulnerabilities that tend to occur when using or developing LLM frameworks, illustrated with specific CVEs, and learn lessons from each vulnerability. We will also introduce countermeasures that developers should be aware of based on these lessons.&lt;/p&gt;</description>
    </item>
  </channel>
</rss>
