Skip to main content

System status

Coverage is stale.

Collection is paused. Latest public event: Aug 21, 2026 (11 days ago).

← Intel index

This coverage is stale.

Last updated May 13, 2026 (about 4 months ago).

people · May 13, 2026

SentinelOne Discloses CVE-2025-3225 XML Entity Expansion DoS in LlamaIndex

Share the canonical public link.

Share as image

SentinelOne disclosed CVE-2025-3225 on May 11, 2026, an XML entity expansion denial-of-service vulnerability in LlamaIndex allowing attackers to crash processes via malicious inputs. The flaw impacts XML parsing in RAG pipelines, differing from previous versions without entity blocking, and requires upgrading to v0.12.29 incorporating defusedxml dependency. The patch routes parsing through defusedxml.ElementTree to prevent attacks, as detailed in GitHub commit 4f6ee06 from May 11, 2026. LlamaIndex team integrated MicroSandbox for agent isolation in sandboxed-lit release on May 11, 2026.

The body describes a specific vulnerability disclosure (CVE-2025-3225) in LlamaIndex, including technical details like affected components (XML parsing in RAG pipelines) and fixes (upgrade to v0.12.29 with defusedxml), which qualifies as a real but moderately impactful security event rather than a major company-defining pivot. It has high information density with multiple verifiable facts such as dates (May 11, 2026), version numbers (v0.12.29), commit hash (4f6ee06), and product names (LlamaIndex, MicroSandbox). The analysis field is explicitly '(none)', providing no strategic insight beyond the headline.

Supporting evidence