CodexGuild Knowledge Base
LlamaIndex Vulnerable to Denial of Service (DoS)
Canonical as of May 10, 2025
LlamaIndex Vulnerable to Denial of Service (DoS)
High severity. Affects llama-index >= 0.12.15, < 0.12.21. Upgrade to 0.12.21 or later.
CVE-2025-1752 / GHSA-7c85-87cp-mr6g · severity: high · CVSS 7.5 · PyPI
Affected
llama-index>= 0.12.15, < 0.12.21 → fixed in 0.12.21
Details
A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically the lack of proper implementation of the max_depth parameter in the get_article_urls function. This allows an attacker to exhaust Python's recursion limit through repeated function calls, leading to resource consumption and ultimately crashing the Python process.
Source: GHSA-7c85-87cp-mr6g — GitHub Advisory Database (CC-BY-4.0).