Skip to content
MediumVulnerability

GHSA-jvpf-xf32-2w4q: LlamaIndex Uncontrolled Resource Consumption vulnerability

Published
Record updated
View JSON
Affected
  • llama-index < 0.12.9
Fixed in
0.12.9
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.7%

Summary

A flaw in the KnowledgeBaseWebReader class of the run-llama/llama_index repository, version latest, lets an attacker control a URL variable so that it contains the root URL. This triggers infinite recursive calls to the get_article_urls method, which exhausts system resources and can crash the application, resulting in a Denial of Service.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.