High severity7.5NVD Advisory· Published Jul 7, 2025· Updated Jun 17, 2026
CVE-2025-3225
CVE-2025-3225
Description
An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
llama-index-readers-papersPyPI | < 0.3.2 | 0.3.2 |
Affected products
3- Range: unspecified
Patches
Vulnerability mechanics
References
4- github.com/run-llama/llama_index/commit/4f6ee062b19212106a2632af9c9521fc7f0a3584nvdPatchWEB
- huntr.com/bounties/e33c0699-e9a2-49aa-837b-5363205637a2nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-w42r-mrx7-c633ghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-3225ghsaADVISORY
News mentions
0No linked articles in our index yet.