icon

We found results for “

CVE-2024-12911

Good to know:

icon
icon

Date: March 20, 2025

A vulnerability in the "default_jsonalyzer" function of the "JSONalyzeQueryEngine" in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.

Severity Score

Severity Score

Weakness Type (CWE)

Creation of Temporary File in Directory with Insecure Permissions

CWE-379

Top Fix

icon

Upgrade Version

Upgrade to version llama-index-core - 0.12.3;llama-index-core - 0.12.3;llama-index - 0.12.3;https://github.com/run-llama/llama_index.git - v0.12.3

Learn More

CVSS v3.1

Base Score:
Attack Vector (AV): NETWORK
Attack Complexity (AC): LOW
Privileges Required (PR): NONE
User Interaction (UI): REQUIRED
Scope (S): UNCHANGED
Confidentiality (C): NONE
Integrity (I): LOW
Availability (A): HIGH

Do you need more information?

Contact Us