Skip to content
HighVulnerability

GHSA-7c85-87cp-mr6g: LlamaIndex Vulnerable to Denial of Service (DoS)

Published
Record updated
View JSON
Affected
  • llama-index >= 0.12.15, < 0.12.21
Fixed in
0.12.21
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.5%

Summary

A Denial of Service vulnerability affects the KnowledgeBaseWebReader class in the run-llama/llama_index project, reported against version ~ latest(v0.12.15). The flaw stems from the max_depth parameter not being properly enforced in the get_article_urls function. An attacker can exhaust Python's recursion limit through repeated function calls, consuming resources and crashing the Python process.

Mitigation

The source does not state a fix yet. Check the original advisory for updates.