CodexGuild Knowledge Base
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
Canonical as of Mar 20, 2025
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
High severity. Affects llama-index < 0.12.3. Upgrade to 0.12.3 or later.
CVE-2024-12911 / GHSA-jmgm-gx32-vp4w · severity: high · CVSS 7.1 · PyPI
Affected
llama-index< 0.12.3 → fixed in 0.12.3
Details
A vulnerability in the default_jsonalyzer function of the JSONalyzeQueryEngine in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.12.3.
Source: GHSA-jmgm-gx32-vp4w — GitHub Advisory Database (CC-BY-4.0).