Skip to content
MediumVulnerability

GHSA-488g-hw5f-x29p: llama-index-core vulnerable to Uncontrolled Resource Consumption

Published
Record updated
View JSON
Affected
  • llama-index-core < 0.12.41
Fixed in
0.12.41
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.4%

Summary

The SimpleDirectoryReader component in llama_index.core version 0.12.23 has an uncontrolled memory consumption flaw. The user-specified num_files_limit is applied only after all files in a directory are loaded into memory, which can exhaust memory and degrade performance, especially in resource-limited environments.

Mitigation

Fixed in version 0.12.41.