GHSA-jgvr-6x5w-hx5w — kcl-lib
GHSA-jgvr-6x5w-hx5w is a remote code execution vulnerability in kcl-lib. A fix is available for kcl-lib — see the affected versions and patch details below.
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
Real-World Exposure
kcl-lib🐍zoo-kclReal-time download stats are indexed for npm and PyPI packages. This vulnerability affects crates.io, PyPI packages — download data is not available via public APIs for these ecosystems.
Description
Impact
Feeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive expression -> unnecessarily_bracketed -> expression path. With enough nesting, the call stack grows until it exceeds the process stack limit, causing a stack overflow.
Affected Packages
| Ecosystem | Package | Vulnerable range | Fix |
|---|---|---|---|
| 🦀crates.io | kcl-lib | all versions | 0.3.129cargo update -p kcl-lib --precise 0.3.129 |
| 🐍PyPI | zoo-kcl | all versions | 0.3.129pip install --upgrade 'zoo-kcl==0.3.129' |
Detection & mitigation playbook
Open-source dependencyDetect
Scan your dependency tree (package-lock.json, pnpm-lock.yaml, requirements.txt, go.sum, etc.) for kcl-lib, including transitive dependencies — a direct dependency you never call can still pull in a vulnerable version.
Fix
Update kcl-lib to 0.3.129 or later, then make sure no transitive (indirect) dependency still pins the vulnerable range — O3 confirms GHSA-jgvr-6x5w-hx5w is resolved across your whole dependency graph.
Workarounds
Stop feeding it untrusted input: reject or quarantine files and payloads from unverified sources until you can upgrade, restrict accepted formats to the ones you actually need, and run the parsing or decoding step in a least-privileged sandbox or short-lived worker so a crash or corrupted read cannot reach the rest of the process.
Frequently Asked Questions
Is GHSA-jgvr-6x5w-hx5w in your dependencies?
Find it across crates.io, PyPI, including transitive dependencies.