CVE-2025-3044
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in version 0.12.28.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 5.3
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N
- EPSS probability
- 0.28%
- CWE
- CWE-440
- Published
- 2025-07-07
- Last modified
- 2026-03-12
Affected products
- run-llama run-llama/llama_index
Weakness type
Related vulnerabilities
- CVE-2026-16769 — RS9116W/SiWx917 plaintext pause encryption request causes DOS
- CVE-2026-65934 — BT122 plaintext pause encryption request causes DOS
- CVE-2026-65932 — BT122 stops advertising
- CVE-2026-8806 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module
- CVE-2026-42752 — WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability
- CVE-2026-49316 — Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
- CVE-2026-42534 — Jostle logic bypass degrades resolution performance
- CVE-2026-41136 — free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer