CVE-2025-6211
A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. This can cause loss of semantically or legally important document content, breakage of parent-child chunk hierarchies, and inaccurate or hallucinated responses in AI outputs. The issue is resolved in version 0.3.1.
Scoring
- Severity
- MEDIUM
- CVSS base score
- 6.5
- CVSS vector
- CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
- EPSS probability
- 0.32%
- CWE
- CWE-440
- Published
- 2025-07-10
- Last modified
- 2026-03-12
Affected products
- run-llama run-llama/llama_index
Weakness type
Related vulnerabilities
- CVE-2026-16769 — RS9116W/SiWx917 plaintext pause encryption request causes DOS
- CVE-2026-65934 — BT122 plaintext pause encryption request causes DOS
- CVE-2026-65932 — BT122 stops advertising
- CVE-2026-8806 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module
- CVE-2026-42752 — WordPress Stripe Payments plugin <= 2.0.98 - Bypass Vulnerability vulnerability
- CVE-2026-49316 — Indian Scout Bobber 2025 WCM CAN bus-off attack silently bypasses anti-theft shutdown
- CVE-2026-42534 — Jostle logic bypass degrades resolution performance
- CVE-2026-41136 — free5GC AMF missing default case in Content-Type switch in HTTPUEContextTransfer