Skip to content
LlamaIndexPYSEC-2025-250

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS)

High7.5CVE-2025-3225 · Published Jul 7, 2025 · updated Jul 13, 2026

Source advisory

Affected versions

PackageAffectedFixed in
llama-index
PyPI
>= 0.12.21, < 0.12.290.12.29
Details and references

An XML Entity Expansion vulnerability, also known as a 'billion laughs' attack, exists in the sitemap parser of the run-llama/llama_index repository, specifically affecting version v0.12.21. This vulnerability allows an attacker to supply a malicious Sitemap XML, leading to a Denial of Service (DoS) by exhausting system memory and potentially causing a system crash. The issue is resolved in version v0.12.29.

CVSS 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
Severity from
the CVSS score
Also known as
CVE-2025-3225, GHSA-w42r-mrx7-c633, PYSEC-2026-1570

More LlamaIndex advisories

All LlamaIndex
DateAdvisory
Jul 72025LlamaIndex has Incomplete Documentation of Program Execution related to JsonPickleSerializer component
CVE-2025-3108Medium5.0fixed in 0.12.41
Jul 72025A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other,
CVE-2025-3044Medium5.3fixed in 0.12.28
Jul 72025A vulnerability in the `ObsidianReader` class of the run-llama/llama_index repository, versions 0.12.23 to 0.12.28, allows for arbitrary file read through symbolic links. The `ObsidianReader` fails to resolve symlinks to their real paths and does not validate whether the resolved paths lie within th
CVE-2025-3046High7.5fixed in 0.12.28
Jul 72025A vulnerability in the ObsidianReader class of the run-llama/llama_index repository, specifically in version 0.12.27, allows for hardlink-based path traversal. This flaw permits attackers to bypass path restrictions and access sensitive system files, such as /etc/passwd, by exploiting hardlinks. The
CVE-2025-6210Medium6.2fixed in 0.5.2
Jul 72025LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsing
CVE-2025-5472Medium6.5fixed in 0.12.38
Jul 72025LlamaIndex vulnerable to Path Traversal attack through its encode_image function
CVE-2025-6209High7.5fixed in 0.12.41

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.