Skip to content
LlamaIndexGHSA-jvpf-xf32-2w4q

LlamaIndex Uncontrolled Resource Consumption vulnerability

Medium5.9CVE-2024-12910 · Published Mar 20, 2025 · updated Oct 15, 2025

A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the `get_article_urls` method, exhausting system resources and potentially crashing the application.

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index
PyPI
< 0.12.90.12.9
Details and references

More LlamaIndex advisories

All LlamaIndex
Advisory
llama_index vulnerable to SQL Injection
Critical9.8Jun 5, 2025
LlamaIndex: SQL injection
Critical9.8Jun 2, 2025
LlamaIndex: command injection
High7.8May 28, 2025
LlamaIndex Vulnerable to Denial of Service (DoS)
High7.5May 10, 2025
LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions
High7.1Mar 20, 2025
LlamaIndex Improper Handling of Exceptional Conditions vulnerability
High7.5Mar 20, 2025

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.