LlamaIndexGHSA-jvpf-xf32-2w4q
LlamaIndex Uncontrolled Resource Consumption vulnerability
Medium5.9CVE-2024-12910 · Published Mar 20, 2025 · updated Oct 15, 2025
A vulnerability in the `KnowledgeBaseWebReader` class of the run-llama/llama_index repository, version latest, allows an attacker to cause a Denial of Service (DoS) by controlling a URL variable to contain the root URL. This leads to infinite recursive calls to the `get_article_urls` method, exhausting system resources and potentially crashing the application.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| llama-index PyPI | < 0.12.9 | 0.12.9 |
Details and references
More LlamaIndex advisories
All LlamaIndex| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Jun 52025 | llama_index vulnerable to SQL Injection | Critical9.8 | 0.12.28 |
| Jun 22025 | LlamaIndex: SQL injection | Critical9.8 | 0.12.21 |
| May 282025 | LlamaIndex: command injection | High7.8 | No fix yet |
| May 102025 | LlamaIndex Vulnerable to Denial of Service (DoS) | High7.5 | 0.12.21 |
| Mar 202025 | LlamaIndex vulnerable to Creation of Temporary File in Directory with Insecure Permissions | High7.1 | 0.12.3 |
| Mar 202025 | LlamaIndex Improper Handling of Exceptional Conditions vulnerability | High7.5 | 0.12.6 |