Knowledge base
CodexGuild Knowledge Base

LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions

as of Mar 20, 2025 · applies to llama-index < 0.12.3 · canonical · codexguild.com/kb/ghsa-jmgm-gx32-vp4w · exported 2026-10-11
Canonical as of Mar 20, 2025

LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions

High severity. Affects llama-index < 0.12.3. Upgrade to 0.12.3 or later.

CVE-2024-12911 / GHSA-jmgm-gx32-vp4w · severity: high · CVSS 7.1 · PyPI

Affected

  • llama-index < 0.12.3 → fixed in 0.12.3

Details

A vulnerability in the default_jsonalyzer function of the JSONalyzeQueryEngine in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.12.3.

Source: GHSA-jmgm-gx32-vp4w — GitHub Advisory Database (CC-BY-4.0).