mediumVulnerability

GHSA-jgvr-6x5w-hx5w

### Impact Feeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive `expression` -> `unnecessarily_bracketed` -> `expression` path. With enough nesting, the call stack grows until it exceeds the process stack limit, causing a stack overflow.

Properties

ghsa_id
GHSA-jgvr-6x5w-hx5w
severity
medium
summary
Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service
cve_id
GHSA-jgvr-6x5w-hx5w
is_ghsa_only
true
ghsa_published
2026-08-20T18:34:05Z
source_url
https://github.com/advisories/GHSA-jgvr-6x5w-hx5w
ghsa_updated
2026-08-20T18:34:07Z

Related Entities (6)

HAS_WEAKNESS (1)

[Weakness]Allocation of Resources Without Limits or Throttling

REPORTED_BY (1)

[Source]GitHub Advisory Database

VULNERABLE_TO (2)

[Software]rust/kcl-lib
[Software]pip/zoo-kcl

AFFECTS (2)

[Software]rust/kcl-lib
[Software]pip/zoo-kcl

Explore deeper with Ninja Signal's threat intelligence graph

GHSA-jgvr-6x5w-hx5w — Ninja Signal Threat Intelligence | Ninja Signal