Executive brief
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser
Affected products
- PyPI llama-index
- PyPI llama-index-readers-papers
Junglewise Threat Intelligence
CVE-2025-3225 · Severity: low · CVSS 3 · Published 2026-07-07
Technologies: llama-index (PyPI). Vendors: PyPI.
LlamaIndex has an XML Entity Expansion vulnerability in its sitemap parser