{"id":"CVE-2024-12911","aliases":["GHSA-jmgm-gx32-vp4w","PYSEC-2026-1555"],"url":"https://o3.security/vulnerability/CVE-2024-12911","summary":"SQL Injection in run-llama/llama_index","details":"A vulnerability in the `default_jsonalyzer` function of the `JSONalyzeQueryEngine` in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.5.1.","published":"2025-03-20T10:09:44.583Z","modified":"2026-07-15T01:49:16.091608956Z","cvss":{"score":7.1,"severity":"HIGH","vector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"PyPI","name":"llama-index","fixedVersion":"0.12.3"}],"fix":{"url":"https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e","label":"run-llama/llama_index@bf28207"},"references":[{"type":"WEB","url":"https://huntr.com/bounties/095f9e67-311d-494c-99c5-5e61a0adb8f3"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2024/12xxx/CVE-2024-12911.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2024-12911"},{"type":"FIX","url":"https://github.com/run-llama/llama_index/commit/bf282074e20e7dafd5e2066137dcd4cd17c3fb9e"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-07-15T01:49:16.091608956Z"}}