CVE-2025-3044
NONE EPSS 19.9%
Published Jul 7, 202511mo ago · Modified Jun 17, 20261w ago
Published Jul 7, 2025 11mo ago
Last Modified Jun 17, 2026 1w ago
Description
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in version 0.12.28.
Threat Intelligence
EPSS Exploit Probability
19.9% percentile
Exploit & Patch Status
Public Exploit Known
Patch Available
Weaknesses 1
CWE-440
Affected Products 1
| Vendor | Product | Version | Range |
|---|---|---|---|
| llamaindex | llamaindex | * | <0.12.28 |
References 2
- github.com https://github.com/run-llama/llama_index/commit/0008041e8dde8e519621388e5d6f558bde6ef42e
- huntr.com https://huntr.com/bounties/80182c3a-876f-422f-8bac-38267e0345d6
Remediation
- github.com https://github.com/run-llama/llama_index/commit/0008041e8dde8e519621388e5d6f558bde6ef42e