A vulnerability in the default_jsonalyzer function of the JSONalyzeQueryEngine in the run-llama/llama_index repository allows for SQL injection via prompt injection. This can lead to arbitrary file creation and Denial-of-Service (DoS) attacks. The vulnerability affects the latest version and is fixed in version 0.12.3.
{
"nvd_published_at": "2025-03-20T10:15:32Z",
"github_reviewed": true,
"cwe_ids": [
"CWE-379",
"CWE-89"
],
"github_reviewed_at": "2025-03-21T18:49:08Z",
"severity": "HIGH"
}