HIGH7.1
PYSEC-2026-1555
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
Quick fix
PYSEC-2026-1555 — llama-index: upgrade to the fixed version with the command below.
pip install --upgrade 'llama-index>=0.12.3'Details
A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.12.3.
Are you affected?
Enter the version of the package you're using.
Affected packages
References
- https://nvd.nist.gov/vuln/detail/CVE-2024-12911[ADVISORY]
- https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e[WEB]
- https://github.com/run-llama/llama_index[PACKAGE]
- https://huntr.com/bounties/095f9e67-311d-494c-99c5-5e61a0adb8f3[WEB]
- https://pypi.org/project/llama-index[PACKAGE]
- https://github.com/advisories/GHSA-jmgm-gx32-vp4w[ADVISORY]