Junglewise Threat Intelligence

CVE-2025-3225: PYSEC-2026-1570 - LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

CVE-2025-3225 · Severity: low · CVSS 3 · Published 2026-07-07

Technologies: llama-index (PyPI). Vendors: PyPI.

Executive brief

LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser

Affected products

  • PyPI llama-index
  • PyPI llama-index-readers-papers

Related threats