A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in version 0.12.28.
References
Link | Resource |
---|---|
https://github.com/run-llama/llama_index/commit/0008041e8dde8e519621388e5d6f558bde6ef42e | Patch |
https://huntr.com/bounties/80182c3a-876f-422f-8bac-38267e0345d6 | Exploit Third Party Advisory |
https://huntr.com/bounties/80182c3a-876f-422f-8bac-38267e0345d6 | Exploit Third Party Advisory |
Configurations
History
30 Jul 2025, 21:28
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* | |
First Time |
Llamaindex llamaindex
Llamaindex |
|
References | () https://github.com/run-llama/llama_index/commit/0008041e8dde8e519621388e5d6f558bde6ef42e - Patch | |
References | () https://huntr.com/bounties/80182c3a-876f-422f-8bac-38267e0345d6 - Exploit, Third Party Advisory |
08 Jul 2025, 16:18
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
07 Jul 2025, 16:15
Type | Values Removed | Values Added |
---|---|---|
References | () https://huntr.com/bounties/80182c3a-876f-422f-8bac-38267e0345d6 - |
07 Jul 2025, 10:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-07-07 10:15
Updated : 2025-07-30 21:28
NVD link : CVE-2025-3044
Mitre link : CVE-2025-3044
CVE.ORG link : CVE-2025-3044
JSON object : View
Products Affected
llamaindex
- llamaindex
CWE
CWE-440
Expected Behavior Violation