A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
References
Link | Resource |
---|---|
https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e | Patch |
https://huntr.com/bounties/095f9e67-311d-494c-99c5-5e61a0adb8f3 | Exploit Third Party Advisory |
Configurations
History
30 Jul 2025, 00:56
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
References | () https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e - Patch | |
References | () https://huntr.com/bounties/095f9e67-311d-494c-99c5-5e61a0adb8f3 - Exploit, Third Party Advisory | |
First Time |
Llamaindex llamaindex
Llamaindex |
|
Summary |
|
20 Mar 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-07-30 00:56
NVD link : CVE-2024-12911
Mitre link : CVE-2024-12911
CVE.ORG link : CVE-2024-12911
JSON object : View
Products Affected
llamaindex
- llamaindex
CWE
CWE-379
Creation of Temporary File in Directory with Insecure Permissions