PT-2025-12158 · Unknown · Llama Index

Published

2025-03-20

·

Updated

2025-07-30

·

CVE-2024-12911

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Name of the Vulnerable Software and Affected Versions llama index versions prior to 0.5.1 llama index versions prior to 0.12.3
Description A vulnerability exists in the default jsonalyzer function of the JSONalyzeQueryEngine. This allows for SQL injection via prompt injection, potentially leading to arbitrary file creation and Denial-of-Service (DoS) attacks.
Recommendations Update to llama index version 0.5.1 or later. Update to llama index version 0.12.3 or later.

Exploit

Fix

DoS

SQL injection

Weakness Enumeration

Related Identifiers

CVE-2024-12911
GHSA-JMGM-GX32-VP4W

Affected Products

Llama Index