GHSA-5hq9-5r78-2gjh · Severity: medium · Ecosystem: pip — LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. This can cause loss of semantically or legally important document content, breakage of parent-child chunk hierarchies, and inaccurate or hallucinated responses in AI outputs. The issue is resolved in version 0.3.1.
Conclusion & alert: CVE-2025-6211 is rated Exploit Available (59.9/100): CVSS Medium severity, with medium exploitation likelihood (EPSS 0.30%). Core evidence: 1 public exploit reference(s) are indexed (Exploit-DB). Mandatory action: Public exploits are available—assess exposure, apply mitigations, and prioritize patching.
Risk is dynamic; we continuously reassess and refresh what is shown on this page as upstream context changes.
| EDB-ID | Source | Kind | Published | Link |
|---|---|---|---|---|
| — | nvd_ref | exploit_tag | Exploit-DB ↗ |
EPSS lead: Daily EPSS estimates relative likelihood of exploitation; percentile ranks this CVE among scored vulnerabilities (higher = more severe relative rank).
| # | Date | Old EPSS score | New EPSS score | Delta (New - Old) |
|---|---|---|---|---|
| 1 | 2026-05-06 | 0.07% | 0.30% | +0.24% |
| 2 | 2025-08-21 | 0.04% | 0.07% | +0.03% |
| 3 | 2025-07-11 | — | 0.04% | — |
Full EPSS history (3 records total)
CVSS metrics for this CVE.
| Base score | Version | Severity | Vector | Exploitability | Impact | Score source |
|---|---|---|---|---|---|---|
| 6.5 | 3.0 | MEDIUM |
|
3.9 | 2.5 | [email protected] |
GHSA-5hq9-5r78-2gjh · Severity: medium · Ecosystem: pip — LlamaIndex vulnerable to data loss through hash collisions in its DocugamiReader class
| vendor | priority | summary | link |
|---|---|---|---|
redhat
|
medium | — | https://access.redhat.com/security/cve/CVE-2025-6211 |
| Vendor | Product | Version | Raw CPE |
|---|---|---|---|
| llamaindex | llamaindex | < 0.3.1 | cpe:2.3:a:llamaindex:llamaindex:*:*:*:*:*:*:*:* |
| URL | Tags |
|---|---|
| https://github.com/run-llama/llama_index/commit/29b2e07e64ed7d302b1cc058185560b28eaa1352 | Patch |
| https://huntr.com/bounties/1a48a011-a3c5-4979-9ffc-9652280bc389 | Exploit Third Party Advisory |