# CVE-2025-21604

## Summary

- **CVE ID:** CVE-2025-21604
- **Severity:** MEDIUM
- **CVSS Score:** 6.9 (CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N)
- **CWE:** CWE-328
- **Published:** Jan 6, 2025
- **Last Modified:** Mar 12, 2026

## Description

LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue is fixed in 3.5.0.

## Affected Products

- moyangzhan — langchain4j-aideepin (< 3.5.0)

## References

- [CNA](https://github.com/moyangzhan/langchain4j-aideepin/security/advisories/GHSA-cv5r-73vf-8x7v)
- [CNA](https://github.com/moyangzhan/langchain4j-aideepin/commit/3cf625c5044a151a8cbcbdf98e10b4b46b8a975a)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.26%
- **EPSS Percentile:** 17.4

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._