A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. This can cause loss of semantically or legally important document content, breakage of parent-child chunk hierarchies, and inaccurate or hallucinated responses in AI outputs. The issue is resolved in version 0.3.1.
History

Wed, 30 Jul 2025 20:15:00 +0000

Type Values Removed Values Added
First Time appeared Llamaindex
Llamaindex llamaindex
CPEs cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:*
Vendors & Products Llamaindex
Llamaindex llamaindex

Wed, 16 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}

epss

{'score': 0.00048}


Fri, 11 Jul 2025 13:45:00 +0000

Type Values Removed Values Added
Metrics epss

{'score': 0.00036}


Fri, 11 Jul 2025 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

epss

{}

threat_severity

Moderate


Thu, 10 Jul 2025 16:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'poc', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 10 Jul 2025 13:15:00 +0000

Type Values Removed Values Added
Description A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. This can cause loss of semantically or legally important document content, breakage of parent-child chunk hierarchies, and inaccurate or hallucinated responses in AI outputs. The issue is resolved in version 0.3.1.
Title MD5 Hash Collision in run-llama/llama_index
Weaknesses CWE-440
References
Metrics cvssV3_0

{'score': 6.5, 'vector': 'CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L'}


cve-icon MITRE

Status: PUBLISHED

Assigner: @huntr_ai

Published: 2025-07-10T13:04:34.401Z

Updated: 2025-07-10T15:13:12.599Z

Reserved: 2025-06-17T17:36:01.333Z

Link: CVE-2025-6211

cve-icon Vulnrichment

Updated: 2025-07-10T15:13:03.316Z

cve-icon NVD

Status : Analyzed

Published: 2025-07-10T13:15:23.137

Modified: 2025-07-30T20:00:35.440

Link: CVE-2025-6211

cve-icon Redhat

Severity : Moderate

Publid Date: 2025-07-10T13:04:34Z

Links: CVE-2025-6211 - Bugzilla