Skip to content
LlamaIndexGHSA-jmgm-gx32-vp4w

LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions

High7.1CVE-2024-12911 · Published Mar 20, 2025 · updated Jul 7, 2026

A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.12.3.

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index
PyPI
< 0.12.30.12.3
Details and references

More LlamaIndex advisories

All LlamaIndex
Advisory
llama_index vulnerable to SQL Injection
Critical9.8Jun 5, 2025
LlamaIndex: SQL injection
Critical9.8Jun 2, 2025
LlamaIndex: command injection
High7.8May 28, 2025
LlamaIndex Vulnerable to Denial of Service (DoS)
High7.5May 10, 2025
LlamaIndex Uncontrolled Resource Consumption vulnerability
Medium5.9Mar 20, 2025
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.