Description
A Denial of Service (DoS) vulnerability has been identified in the KnowledgeBaseWebReader class of the run-llama/llama_index project, affecting version ~ latest(v0.12.15). The vulnerability arises due to inappropriate secure coding measures, specifically the lack of proper implementation of the max_depth parameter in the get_article_urls function. This allows an attacker to exhaust Python's recursion limit through repeated function calls, leading to resource consumption and ultimately crashing the Python process.
INFO
Published Date :
2025-05-10T13:21:30.866Z
Last Modified :
2025-10-15T12:50:06.038Z
Source :
@huntr_ai
AFFECTED PRODUCTS
The following products are affected by CVE-2025-1752 vulnerability.
| Vendors | Products |
|---|---|
| Llamaindex |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2025-1752.