CVE-2025-3225 | run-llama llama_index up to 0.12.28 Sitemap XML xml entity expansion (EUVD-2025-20207)
A vulnerability was found in run-llama llama_index up to 0.12.28. It has been classified as problematic. Affected is an unknown function of the component Sitemap XML Handler. The manipulation leads to xml entity expansion.
This vulnerability is traded as CVE-2025-3225. It is possible to launch the attack remotely. There is no exploit available.
It is recommended to upgrade the affected component.