CodexGuild Knowledge Base
llama-index-core vulnerable to Uncontrolled Resource Consumption
Canonical as of Feb 2, 2026
llama-index-core vulnerable to Uncontrolled Resource Consumption
Medium severity. Affects llama-index-core < 0.12.41. Upgrade to 0.12.41 or later.
CVE-2025-6208 / GHSA-488g-hw5f-x29p · severity: medium · CVSS 5.3 · PyPI
Affected
llama-index-core< 0.12.41 → fixed in 0.12.41
Details
The SimpleDirectoryReader component in llama_index.core version 0.12.23 suffers from uncontrolled memory consumption due to a resource management flaw. The vulnerability arises because the user-specified file limit (num_files_limit) is applied after all files in a directory are loaded into memory. This can lead to memory exhaustion and degraded performance, particularly in environments with limited resources. The issue is resolved in version 0.12.41.
Source: GHSA-488g-hw5f-x29p — GitHub Advisory Database (CC-BY-4.0).