AE-97N3CYDM
Prompt injection in a pandas query engine makes the LLM emit Python that is run with exec, giving code execution (CVE-2023-39662)
PROMPT INJECTIONseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
PandasQueryEngine executed LLM-generated Python with exec. A one-line jailbreak prompt made the model return attacker-chosen code that ran on the host; a first sandboxing fix was shown to be bypassable and was followed by a second fix blocking private/dunder access.
- Framework / agent
- LlamaIndex · LLM query engine that generates and executes code
- Remediation attempts
- FAILEDTESTED
- Recurrence
- not documented
- Source languages
- en
- Updated
- 2026-09-30
Sources
- GITHUB ISSUE [Bug]: Prompt injection which will lead to RCE — github.com/run-llama/llama_index, retrieved 2026-09-29
- GITHUB PULL REQUEST Remediate RCE vulnerability CVE-2023-39662 — github.com/run-llama/llama_index, retrieved 2026-09-29
- GITHUB PULL REQUEST Remediate RCE vulnerability CVE-2023-39662 - part 2 — github.com/run-llama/llama_index, retrieved 2026-09-29
Symptoms
- A jailbreak prompt causes the query engine to run an OS command that creates a file on the host
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-97N3CYDM. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.