MediumVulnerability
GHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
- Identifiers
- CVE-2025-6211GHSA-5hq9-5r78-2gjh
- Published
- Record updated
- Affected
- llama-index < 0.12.41, fixed in 0.12.41
- llama-index-readers-docugami < 0.3.1, fixed in 0.3.1
- Known exploitation
- Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
- EPSS
- 0.3%
Summary
The DocugamiReader class in run-llama/llama_index, in versions up to but excluding 0.12.41, generates chunk IDs with MD5 hashing. Structurally distinct chunks that contain identical text collide, so one chunk overwrites another. This can lose important document content, break parent-child chunk hierarchies, and produce inaccurate AI responses.
Mitigation
The issue is resolved in version 0.3.1.
Affected packages in the Exposure Registry
Matched by package name and ecosystem. Each entry shows whether the package delegates to a language model and how many tracked packages depend on it.
- llama-indexPyPILLM dependency since 2023-02-16 · 12 tracked dependents
Related items
- HighCVE-2024-58339: LlamaIndex VannaQueryEngine uncontrolled resource consumption in custom_querySame vendor · NVD/CVE Database
- HighGHSA-rg9h-vx28-xxp5: llama-index has Insecure Temporary FileSame vendor · GitHub Advisory Database
- HighGHSA-7753-xrfw-ch36: LlamaIndex affected by a Denial of Service (DOS) in JSONReaderSame vendor · GitHub Advisory Database
- HighGHSA-2rhq-96q8-4vjq: LlamaIndex vulnerable to Path Traversal attack through its encode_image functionSame vendor · GitHub Advisory Database
- MediumGHSA-3wxx-q3gv-pvvv: LlamaIndex vulnerable to DoS attack through uncontrolled recursive JSON parsingSame vendor · GitHub Advisory Database