LlamaIndexGHSA-jmgm-gx32-vp4w
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
High7.1CVE-2024-12911 · Published Mar 20, 2025 · updated Jul 7, 2026
A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.12.3.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| llama-index PyPI | < 0.12.3 | 0.12.3 |
Details and references
More LlamaIndex advisories
All LlamaIndex| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 52025 | llama_index vulnerable to SQL Injection | Critical9.8 | 0.12.28 |
| Jun 22025 | LlamaIndex: SQL injection | Critical9.8 | 0.12.21 |
| May 282025 | LlamaIndex: command injection | High7.8 | No fix yet |
| May 102025 | LlamaIndex Vulnerable to Denial of Service (DoS) | High7.5 | 0.12.21 |
| Mar 202025 | LlamaIndex Uncontrolled Resource Consumption vulnerability | Medium5.9 | 0.12.9 |
| Mar 202025 | LlamaIndex Improper Handling of Exceptional Conditions vulnerability | High7.5 | 0.12.6 |