MediumVulnerability
GHSA-488g-hw5f-x29p: llama-index-core vulnerable to Uncontrolled Resource Consumption
- Identifiers
- CVE-2025-6208GHSA-488g-hw5f-x29p
- Published
- Record updated
- Affected
- llama-index-core < 0.12.41
- Fixed in
- 0.12.41
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.4%
Summary
The SimpleDirectoryReader component in llama_index.core version 0.12.23 has an uncontrolled memory consumption flaw. The user-specified num_files_limit is applied only after all files in a directory are loaded into memory, which can exhaust memory and degrade performance, especially in resource-limited environments.
Mitigation
Fixed in version 0.12.41.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-index-corePyPILLM dependency since 2024-02-02 · 34 tracked dependents
Related items
- HighHermes Agent - Pre-Authentication Disk ConsumptionSimilar attack · Tenable Research Advisories
- MediumHermes Agent - Pre-Authentication Memory ExhaustionSimilar attack · Tenable Research Advisories
- MediumGHSA-v36g-jcw9-x7cw: Pydantic AI: Excessive resource use when local web fetching converts nested HTMLSimilar attack · GitHub Advisory Database
- MediumGHSA-v2xh-2vp8-57h8: Pydantic AI: Unbounded memory use when downloading remote content via web_fetch or FileUrlSimilar attack · GitHub Advisory Database
- MediumGHSA-fpf4-vwcp-v4hp: Pydantic AI: Event loop blocked by quadratic title extraction in `web_fetch`Similar attack · GitHub Advisory Database