Description

A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.

INFO

Published Date :

2025-03-20T10:09:44.583Z

Last Modified :

2025-10-15T12:50:19.844Z

Source :

@huntr_ai
AFFECTED PRODUCTS

The following products are affected by CVE-2024-12911 vulnerability.

Vendors Products
Llamaindex
  • Llamaindex

CVSS Vulnerability Scoring System

Detailed values of each vector for above chart.
Attack Vector
Attack Complexity
Privileges Required
User Interaction
Scope
Confidentiality Impact
Integrity Impact
Availability Impact