Beveiligingsadvies

CVE-2025-3225

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2025-07-07 09:54:06
Laatst bijgewerkt 2025-07-07 14:59:26
Toegewezen door @huntr_ai
CVSS-score 7.5
Status PUBLISHED

Beschrijving

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29.