CodexGuild Knowledge Base
LlamaIndex Uncontrolled Resource Consumption vulnerability
Canonical as of Mar 20, 2025
LlamaIndex Uncontrolled Resource Consumption vulnerability
Medium severity. Affects llama-index < 0.12.9. Upgrade to 0.12.9 or later.
CVE-2024-12910 / GHSA-jvpf-xf32-2w4q · severity: medium · CVSS 5.9 · PyPI
Affected
llama-index< 0.12.9 → fixed in 0.12.9
Details
A vulnerability in the KnowledgeBaseWebReader class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the get_article_urls method, exhausting system resources and potentially crashing the application.
Source: GHSA-jvpf-xf32-2w4q — GitHub Advisory Database (CC-BY-4.0).