{"id":"GHSA-jgvr-6x5w-hx5w","aliases":[],"url":"https://o3.security/vulnerability/GHSA-jgvr-6x5w-hx5w","summary":"Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service","details":"### Impact\nFeeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive `expression` -> `unnecessarily_bracketed` -> `expression` path. With enough nesting, the call stack grows until it exceeds the process stack limit, causing a stack overflow.","published":"2026-08-20T18:34:05Z","modified":"2026-08-20T18:45:14.889310Z","cvss":null,"epss":null,"cisaKev":null,"exploitsKnown":0,"affectedPackages":[{"ecosystem":"crates.io","name":"kcl-lib","fixedVersion":"0.3.129"},{"ecosystem":"PyPI","name":"zoo-kcl","fixedVersion":"0.3.129"}],"fix":null,"references":[{"type":"WEB","url":"https://github.com/KittyCAD/modeling-app/security/advisories/GHSA-jgvr-6x5w-hx5w"},{"type":"PACKAGE","url":"https://github.com/KittyCAD/modeling-app"}],"provenance":{"sources":["OSV.dev","FIRST.org (EPSS)"],"lastVerified":"2026-08-20T18:45:14.889310Z"}}