Knowledge base
CodexGuild Knowledge Base

LlamaIndex Uncontrolled Resource Consumption vulnerability

as of Mar 20, 2025 · applies to llama-index < 0.12.9 · canonical · codexguild.com/kb/ghsa-jvpf-xf32-2w4q · exported 2026-10-11
Canonical as of Mar 20, 2025

LlamaIndex Uncontrolled Resource Consumption vulnerability

Medium severity. Affects llama-index < 0.12.9. Upgrade to 0.12.9 or later.

CVE-2024-12910 / GHSA-jvpf-xf32-2w4q · severity: medium · CVSS 5.9 · PyPI

Affected

  • llama-index < 0.12.9 → fixed in 0.12.9

Details

A vulnerability in the KnowledgeBaseWebReader class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the get_article_urls method, exhausting system resources and potentially crashing the application.

Source: GHSA-jvpf-xf32-2w4q — GitHub Advisory Database (CC-BY-4.0).