Skip to content
LlamaIndexGHSA-3wxx-q3gv-pvvv

LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing

Medium6.5CVE-2025-5472 · Published Jul 7, 2025 · updated Jul 13, 2026

GitHub advisory

Affected versions

PackageAffectedFixed in
llama-index-core
PyPI
< 0.12.380.12.38
Details and references

The JSONReader in run-llama/llama_index versions 0.12.28 is vulnerable to a stack overflow due to uncontrolled recursive JSON parsing. This vulnerability allows attackers to trigger a Denial of Service (DoS) by submitting deeply nested JSON structures, leading to a RecursionError and crashing applications. The root cause is the unsafe recursive traversal design and lack of depth validation, which makes the JSONReader susceptible to stack overflow when processing deeply nested JSON. This impacts the availability of services, making them unreliable and disrupting workflows. The issue is resolved in version 0.12.38.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Severity from
GitHub (reviewed advisory)
Weakness
CWE-674
Also known as
CVE-2025-5472, PYSEC-2025-251, PYSEC-2026-1559

More LlamaIndex advisories

All LlamaIndex
DateAdvisory
Jul 72025LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-3108Medium5.0fixed in 0.12.41
Jul 72025A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other,
CVE-2025-3044Medium5.3fixed in 0.12.28
Jul 72025A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within th
CVE-2025-3046High7.5fixed in 0.12.28
Jul 72025An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS)
CVE-2025-3225High7.5fixed in 0.12.29
Jul 72025A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. The
CVE-2025-6210Medium6.2fixed in 0.5.2
Jul 72025LlamaIndex vulnerable to Path Traversal attack through its encode_image function
CVE-2025-6209High7.5fixed in 0.12.41

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.