CVE-2024-58339

LlamaIndex (run-llama/llama_index) versions up to and including 0.12.2 contain an uncontrolled resource consumption vulnerability in the VannaPack VannaQueryEngine implementation. The custom_query() logic generates SQL statements from a user-supplied prompt and executes them via vn.run_sql() without enforcing query execution limits In downstream deployments where untrusted users can supply prompts, an attacker can trigger expensive or unbounded SQL operations that exhaust CPU or memory resources, resulting in a denial-of-service condition. The vulnerable execution path occurs in llama_index/packs/vanna/base.py within custom_query().
Configurations

Configuration 1 (hide)

cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:*

History

21 Jan 2026, 18:30

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:*
First Time Llamaindex
Llamaindex llamaindex
References () https://github.com/run-llama/llama_index - () https://github.com/run-llama/llama_index - Product
References () https://huntr.com/bounties/a1d6c30d-fce0-412a-bd22-14e0d4c1fa1f - () https://huntr.com/bounties/a1d6c30d-fce0-412a-bd22-14e0d4c1fa1f - Exploit, Third Party Advisory
References () https://www.llamaindex.ai/ - () https://www.llamaindex.ai/ - Product
References () https://www.vulncheck.com/advisories/llamaindex-vannaqueryengine-sql-execution-allows-resource-exhaustion - () https://www.vulncheck.com/advisories/llamaindex-vannaqueryengine-sql-execution-allows-resource-exhaustion - Third Party Advisory

12 Jan 2026, 23:15

Type Values Removed Values Added
New CVE

Information

Published : 2026-01-12 23:15

Updated : 2026-01-21 18:30


NVD link : CVE-2024-58339

Mitre link : CVE-2024-58339

CVE.ORG link : CVE-2024-58339


JSON object : View

Products Affected

llamaindex

  • llamaindex
CWE
CWE-770

Allocation of Resources Without Limits or Throttling