XML Entity Expansion Vulnerability in run-llama's Llama Index
CVE-2025-3225
What is CVE-2025-3225?
An XML Entity Expansion vulnerability is present in the sitemap parser of the Llama Index repository maintained by run-llama. This vulnerability allows attackers to exploit a flaw in the XML parsing mechanism, commonly referred to as a 'billion laughs' attack. By submitting a carefully crafted malicious Sitemap XML, an attacker can manipulate the system into entering a state of resource exhaustion, leading to a Denial of Service (DoS) scenario where the affected server may crash or become unresponsive. The issue was effectively resolved in version v0.12.29, making it crucial for users to upgrade to prevent potential exploitation.
Affected Version(s)
run-llama/llama_index < unspecified
News Articles

CVE-2025-3225 | run-llama llama_index up to 0.12.28 Sitemap XML xml entity expansion
A vulnerability was found in run-llama llama_index up to 0.12.28. It has been classified as problematic. Affected is an unknown function of the component Sitemap XML Handler. The manipulation lead…
3 weeks ago