Skip to content
MediumVulnerability

GHSA-5hq9-5r78-2gjh: LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class

Published
Record updated
View JSON
Affected
  • llama-index < 0.12.41, fixed in 0.12.41
  • llama-index-readers-docugami < 0.3.1, fixed in 0.3.1
Known exploitation
Not listed in the CISA Known Exploited Vulnerabilities catalog at the last check.
EPSS
0.3%

Summary

The DocugamiReader class in run-llama/llama_index, in versions up to but excluding 0.12.41, generates chunk IDs with MD5 hashing. Structurally distinct chunks that contain identical text collide, so one chunk overwrites another. This can lose important document content, break parent-child chunk hierarchies, and produce inaccurate AI responses.

Mitigation

The issue is resolved in version 0.3.1.