GHSA-jgvr-6x5w-hx5wMediumDisclosed before NVD

Zoo Design Studio: Recursive KCL parsing is vulnerable to denial-of-service

Published
August 20, 2026
Last Modified
August 20, 2026

📋 Description

Impact

Feeding a KCL program that wraps an expression in deep, unnecessary parentheses triggers the parser’s recursive expression -> unnecessarily_bracketed -> expression path. With enough nesting, the call stack grows until it exceeds the process stack limit, causing a stack overflow.

🎯 Affected products2

  • pip/zoo-kcl:< 0.3.129
  • rust/kcl-lib:< 0.2.129

🔗 References (2)