PT-2025-20625 · Run Llama · Llama Index

Published

2025-02-02

·

Updated

2026-01-11

·

CVE-2025-1752

CVSS v2.0

7.8

High

VectorAV:N/AC:L/Au:N/C:N/I:N/A:C
Name of the Vulnerable Software and Affected Versions run-llama/llama index version ~ latest(v0.12.15)
Description A Denial of Service (DoS) issue has been identified in the KnowledgeBaseWebReader class due to inadequate secure coding practices. Specifically, the lack of proper implementation of the max depth parameter in the get article urls function allows an attacker to exhaust Python's recursion limit through repeated function calls. This leads to resource consumption and ultimately crashes the Python process.
Recommendations For version ~ latest(v0.12.15), consider disabling the get article urls function until a patch is available to prevent exploitation. Restrict access to the KnowledgeBaseWebReader class to minimize the risk of resource consumption. Avoid using the max depth parameter in the affected function until the issue is resolved. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

DoS

Uncontrolled Recursion

Resource Exhaustion

Weakness Enumeration

Related Identifiers

BDU:2025-06394
CVE-2025-1752
GHSA-7C85-87CP-MR6G

Affected Products

Llama Index