First published: Thu Mar 20 2025(Updated: )
A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.12.3.
Credit: security@huntr.dev
Affected Software | Affected Version | How to fix |
---|---|---|
pip/llama-index | <0.12.3 | 0.12.3 |
LlamaIndex | <0.5.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-12911 is considered a high-severity vulnerability due to its potential for SQL injection leading to arbitrary file creation and Denial-of-Service attacks.
To fix CVE-2024-12911, update the `llama_index` package to version 0.12.3 or later.
CVE-2024-12911 affects the `llama_index` package version below 0.12.3.
Yes, CVE-2024-12911 can lead to data breaches due to its SQL injection capabilities.
No, CVE-2024-12911 is not exploitable in versions of `llama_index` that are 0.12.3 and above.