We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-3044

MD5 Hash Collision in run-llama/llama_index



Description

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in version 0.12.28.

Reserved 2025-03-31 | Published 2025-07-07 | Updated 2025-07-07 | Assigner @huntr_ai


MEDIUM: 5.3CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Problem types

CWE-440 Expected Behavior Violation

Product status

Any version before 0.12.28
affected

References

huntr.com/bounties/80182c3a-876f-422f-8bac-38267e0345d6

github.com/...ommit/0008041e8dde8e519621388e5d6f558bde6ef42e

cve.org (CVE-2025-3044)

nvd.nist.gov (CVE-2025-3044)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-3044

Support options

Helpdesk Chat, Email, Knowledgebase