A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
Advisories
Source ID Title
EUVD EUVD EUVD-2025-6988 A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
Github GHSA Github GHSA GHSA-jmgm-gx32-vp4w LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Wed, 15 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Wed, 30 Jul 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Llamaindex
Llamaindex llamaindex
CPEs cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:*
Vendors & Products Llamaindex
Llamaindex llamaindex

Wed, 26 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics threat_severity

Important

threat_severity

Moderate


Fri, 21 Mar 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
Title SQL Injection in run-llama/llama_index
Weaknesses CWE-379
References
Metrics cvssV3_0

{'score': 7.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-10-15T12:50:19.844Z

Reserved: 2024-12-24T07:51:29.340Z

Link: CVE-2024-12911

cve-icon Vulnrichment

Updated: 2025-03-20T17:50:17.749Z

cve-icon NVD

Status : Modified

Published: 2025-03-20T10:15:32.083

Modified: 2025-10-15T13:15:41.607

Link: CVE-2024-12911

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-20T10:09:44Z

Links: CVE-2024-12911 - Bugzilla

cve-icon OpenCVE Enrichment

No data.