Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2025-20207 | LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser |
Github GHSA |
GHSA-w42r-mrx7-c633 | LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser |
Wed, 30 Jul 2025 21:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Llamaindex
Llamaindex llamaindex |
|
| CPEs | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Llamaindex
Llamaindex llamaindex |
Sun, 13 Jul 2025 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
epss
|
epss
|
Tue, 08 Jul 2025 00:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
| |
| Metrics |
threat_severity
|
threat_severity
|
Mon, 07 Jul 2025 15:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Mon, 07 Jul 2025 10:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29. | |
| Title | XML Entity Expansion vulnerability in run-llama/llama_index | |
| Weaknesses | CWE-776 | |
| References |
| |
| Metrics |
cvssV3_0
|
Status: PUBLISHED
Assigner: @huntr_ai
Published:
Updated: 2025-07-07T14:59:26.842Z
Reserved: 2025-04-03T15:03:26.975Z
Link: CVE-2025-3225
Updated: 2025-07-07T14:58:08.545Z
Status : Analyzed
Published: 2025-07-07T10:15:27.047
Modified: 2025-07-30T21:24:40.497
Link: CVE-2025-3225
OpenCVE Enrichment
No data.
EUVD
Github GHSA