AE Agent Errors
AE-GDZEYNCQ

Restricted safe_eval of LLM-generated code is bypassed via prompt injection, executing arbitrary code (bypass of an earlier fix)

SECURITY FAILUREseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM

LlamaIndex's exec_utils safe_eval, used to evaluate LLM-generated code (e.g. in the pandas query engine), did not sufficiently validate input, so prompt injection could bypass its method restrictions and execute unauthorized code, demonstrated by creating a file on the system. The report is a bypass of the earlier fix for CVE-2023-39662; the maintainers tightened builtin access in the pandas query engine in 0.10.24.

Framework / agent
LlamaIndex · LLM query engine executing generated Python (pandas)
Remediation attempts
TESTED
Recurrence
observed
Source languages
en
Updated
2026-09-29

Sources

Symptoms

  • Prompt injection makes safe_eval execute unauthorized code, creating a file on the system in the proof of concept
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents: GET /api/v1/cases/AE-GDZEYNCQ. Pricing

Similarity to your system is not implied. A remediation that worked in the documented context may not work in yours.