A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
References
| Link | Resource |
|---|---|
| https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e | Patch |
| https://huntr.com/bounties/095f9e67-311d-494c-99c5-5e61a0adb8f3 | Exploit Third Party Advisory |
Configurations
History
15 Oct 2025, 13:15
| Type | Values Removed | Values Added |
|---|---|---|
| CWE | CWE-89 |
30 Jul 2025, 00:56
| Type | Values Removed | Values Added |
|---|---|---|
| CPE | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
| References | () https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e - Patch | |
| References | () https://huntr.com/bounties/095f9e67-311d-494c-99c5-5e61a0adb8f3 - Exploit, Third Party Advisory | |
| First Time |
Llamaindex
Llamaindex llamaindex |
|
| Summary |
|
20 Mar 2025, 10:15
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2025-03-20 10:15
Updated : 2025-10-15 13:15
NVD link : CVE-2024-12911
Mitre link : CVE-2024-12911
CVE.ORG link : CVE-2024-12911
JSON object : View
Products Affected
llamaindex
- llamaindex
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
