
We found results for “”
CVE-2024-12911
Good to know:


Date: March 20, 2025
A vulnerability in the "default_jsonalyzer" function of the "JSONalyzeQueryEngine" in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.
Severity Score
Related Resources (5)
Severity Score
Weakness Type (CWE)
Creation of Temporary File in Directory with Insecure Permissions
CWE-379Top Fix

Upgrade Version
Upgrade to version llama-index-core - 0.12.3;llama-index-core - 0.12.3;llama-index - 0.12.3;https://github.com/run-llama/llama_index.git - v0.12.3
CVSS v3.1
Base Score: |
|
---|---|
Attack Vector (AV): | NETWORK |
Attack Complexity (AC): | LOW |
Privileges Required (PR): | NONE |
User Interaction (UI): | REQUIRED |
Scope (S): | UNCHANGED |
Confidentiality (C): | NONE |
Integrity (I): | LOW |
Availability (A): | HIGH |