{"data":{"id":"add130a4-0cc8-42be-9bd4-ebf81354a1cb","title":"GHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class ","summary":"The DocugamiReader class in run-llama/llama_index, in versions up to but excluding 0.12.41, generates chunk IDs with MD5 hashing. Structurally distinct chunks that contain identical text collide, so one chunk overwrites another. This can lose important document content, break parent-child chunk hierarchies, and produce inaccurate AI responses.","solution":"The issue is resolved in version 0.3.1.","labels":["security"],"sourceUrl":"https://github.com/advisories/GHSA-5hq9-5r78-2gjh","publishedAt":"2025-07-10T15:31:27.000Z","cveId":"CVE-2025-6211","cweIds":["CWE-440"],"cvssScore":"6.5","cvssSeverity":"medium","severity":"medium","attackType":["other"],"issueType":"vulnerability","affectedPackages":["llama-index@< 0.12.41 (fixed: 0.12.41)","llama-index-readers-docugami@< 0.3.1 (fixed: 0.3.1)"],"affectedPackageNames":["llama-index","llama-index-readers-docugami"],"affectedPackageRefs":["pypi:llama-index","pypi:llama-index-readers-docugami"],"affectedVendors":["LlamaIndex"],"affectedVendorsRaw":["LlamaIndex"],"classifierModel":"claude-haiku-5-5","classifierPromptVersion":"v4","summaryPromptVersion":"v2","headline":null,"headlinePromptVersion":null,"cvssVector":"CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L","attackVector":"network","attackComplexity":"low","privilegesRequired":"none","userInteraction":"none","exploitMaturity":"unknown","epssScore":0.00336,"epssCheckedAt":"2026-10-10T04:57:15.402Z","kevDateAdded":null,"advisoryAliases":["GHSA-5hq9-5r78-2gjh"],"affectedPackagesSource":null,"affectedPackagesCheckedAt":null,"patchAvailable":true,"disclosureDate":"2025-07-10T15:31:27.000Z","capecIds":null,"crossRefCount":0,"attackSophistication":"trivial","impactType":["integrity"],"aiComponentTargeted":"rag","llmSpecific":false,"classifierConfidence":0.9,"researchCategory":null,"atlasIds":null}}