We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-3225

XML Entity Expansion vulnerability in run-llama/llama_index



Description

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29.

Reserved 2025-04-03 | Published 2025-07-07 | Updated 2025-07-07 | Assigner @huntr_ai


HIGH: 7.5CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Problem types

CWE-776 Improper Restriction of Recursive Entity References in DTDs

Product status

Any version before v0.12.29
affected

References

huntr.com/bounties/e33c0699-e9a2-49aa-837b-5363205637a2

github.com/...ommit/4f6ee062b19212106a2632af9c9521fc7f0a3584

cve.org (CVE-2025-3225)

nvd.nist.gov (CVE-2025-3225)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-3225

Support options

Helpdesk Chat, Email, Knowledgebase