CVE-2026-8318 Details
Description
A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by this vulnerability is the function toc_transformer of the file pageindex/page_index.py of the component PDF Table of Contents Handler. The manipulation results in infinite loop. The attack may be launched remotely. The exploit has been released to the public and may be used for attacks. This product operates on a rolling release basis, ensuring continuous delivery. Consequently, there are no version details for either affected or updated releases.
A denial-of-service vulnerability has been identified in VectifyAI PageIndex versions prior to f50e52975313c6716c02b20a119577a1929decba. The issue arises in the PDF Table of Contents Handler component, specifically within the 'toc_transformer' function of 'pageindex/page_index.py'. This vulnerability allows for an infinite loop to be created, which can be exploited remotely. The loop is triggered by a crafted PDF that contains an excessively long Table of Contents, causing the application to repeatedly query the backend LLM API without completion. This not only exhausts processing resources but also rapidly depletes LLM API credits, leading to financial costs.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed May 11, 2026CISA-ADP
Assessed May 11, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/VectifyAI/PageIndex/ | [email protected] | Vendor |
| https://github.com/VectifyAI/PageIndex/issues/174 | [email protected] | ExploitIssue TrackingTechnical DescriptionVendor |
| https://vuldb.com/submit/811273 | [email protected] | Permission Required |
| https://vuldb.com/vuln/362605 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/362605/cti | [email protected] | AdvisoryPermission Required |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-404 | Improper Resource Shutdown or Release | [email protected] |
| CWE-835 | Loop with Unreachable Exit Condition ('Infinite Loop') | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| VectifyAI PageIndex | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 11, 2026 | New CVE Received | [email protected] |
Volerion