Description
A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
Published: 2025-03-20
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
EUVD EUVD EUVD-2025-6988 A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
Github GHSA Github GHSA GHSA-jmgm-gx32-vp4w LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
History

Wed, 15 Oct 2025 13:00:00 +0000

Type Values Removed Values Added
Weaknesses CWE-89

Wed, 30 Jul 2025 01:00:00 +0000

Type Values Removed Values Added
First Time appeared Llamaindex
Llamaindex llamaindex
CPEs cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:*
Vendors & Products Llamaindex
Llamaindex llamaindex

Wed, 26 Mar 2025 03:15:00 +0000

Type Values Removed Values Added
Metrics threat_severity

Important

threat_severity

Moderate


Fri, 21 Mar 2025 02:30:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

threat_severity

Important


Thu, 20 Mar 2025 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 20 Mar 2025 10:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
Title SQL Injection in run-llama/llama_index
Weaknesses CWE-379
References
Metrics cvssV3_0

{'score': 7.1, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H'}


Subscriptions

Llamaindex Llamaindex
cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published:

Updated: 2025-10-15T12:50:19.844Z

Reserved: 2024-12-24T07:51:29.340Z

Link: CVE-2024-12911

cve-icon Vulnrichment

Updated: 2025-03-20T17:50:17.749Z

cve-icon NVD

Status : Modified

Published: 2025-03-20T10:15:32.083

Modified: 2025-10-15T13:15:41.607

Link: CVE-2024-12911

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-03-20T10:09:44Z

Links: CVE-2024-12911 - Bugzilla

cve-icon OpenCVE Enrichment

No data.

Weaknesses