MEDIUM 5.9 PyPI
LlamaIndex Uncontrolled Resource Consumption vulnerability
GHSA-jvpf-xf32-2w4q · CVE-2024-12910 · PYSEC-2025-11
Published · Modified
Description
A vulnerability in the KnowledgeBaseWebReader class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the get_article_urls method, exhausting system resources and potentially crashing the application.
References
- ADVISORY https://nvd.nist.gov/vuln/detail/CVE-2024-12910
- WEB https://github.com/run-llama/llama_index/commit/159ce485a1168100bb219dc1b93133f1121579d9
- WEB https://github.com/pypa/advisory-database/tree/main/vulns/llama-index/PYSEC-2025-11.yaml
- PACKAGE https://github.com/run-llama/llama_index
- WEB https://huntr.com/bounties/27883f22-35ff-49df-aaa5-05031c7d6ad8
Ready to move
Start Securing
Free, no credit card | First findings in minutes