AE-GDZEYNCQ
Restricted safe_eval of LLM-generated code is bypassed via prompt injection, executing arbitrary code (bypass of an earlier fix)
SECURITY FAILUREseverity: CRITICALcause: LIKELYoutcome: RESOLVED UNVERIFIEDconfidence: MEDIUM
LlamaIndex's exec_utils safe_eval, used to evaluate LLM-generated code (e.g. in the pandas query engine), did not sufficiently validate input, so prompt injection could bypass its method restrictions and execute unauthorized code, demonstrated by creating a file on the system. The report is a bypass of the earlier fix for CVE-2023-39662; the maintainers tightened builtin access in the pandas query engine in 0.10.24.
- Framework / agent
- LlamaIndex · LLM query engine executing generated Python (pandas)
- Remediation attempts
- TESTED
- Recurrence
- observed
- Source languages
- en
- Updated
- 2026-09-29
Sources
- SECURITY ADVISORY llama-index-core Prompt Injection vulnerability leading to Arbitrary Code Execution — github.com/advisories, retrieved 2026-09-29
- GITHUB COMMIT stricter access to builting in pandas query engine (#12278) — github.com/run-llama/llama_index, retrieved 2026-09-29
Symptoms
- Prompt injection makes safe_eval execute unauthorized code, creating a file on the system in the proof of concept
The full record — root-cause evidence, every remediation attempt with its status and verification, failed attempts, patch references, verbatim quotes and recurrence — is a paid lookup (0.018 USDC via x402). Agents:
GET /api/v1/cases/AE-GDZEYNCQ. PricingSimilarity to your system is not implied. A remediation that worked in the documented context may not work in yours.