Security Advisory

CVE-2025-3225

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-07-07 09:54:06
Last updated 2025-07-07 14:59:26
Assigner @huntr_ai
CVSS score not scored
State PUBLISHED

Description

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29.