CVE-2025-6211
Last modified
CVE-2025-6211 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. EPSS estimates a 0.31% chance of exploitation in the next 30 days.
Description
A vulnerability in the DocugamiReader class of the run-llama/llama_index repository, up to version 0.12.28, involves the use of MD5 hashing to generate IDs for document chunks. This approach leads to hash collisions when structurally distinct chunks contain identical text, resulting in one chunk overwriting another. This can cause loss of semantically or legally important document content, breakage of parent-child chunk hierarchies, and inaccurate or hallucinated responses in AI outputs. The issue is resolved in version 0.3.1.
Metrics
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:L
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Llamaindex | Llamaindex | < 0.3.1 |
References
- https://huntr.com/bounties/1a48a011-a3c5-4979-9ffc-9652280bc389Exploit, Third Party Advisory
- https://huntr.com/bounties/1a48a011-a3c5-4979-9ffc-9652280bc389Exploit, Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-6211?
How severe is CVE-2025-6211?
How do I fix CVE-2025-6211?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2025
- CVE-2025-62103Cross-Site Request Forgery (CSRF) vulnerability in wpmediado…4.3
- CVE-2025-62104Missing Authorization vulnerability in Navneil Naicker ACF G…4.3
- CVE-2025-62106Missing Authorization vulnerability in Mario Peshev WP-CRM S…5.4
- CVE-2025-62107Cross-Site Request Forgery (CSRF) vulnerability in PluginOps…4.3
- CVE-2025-62108Missing Authorization vulnerability in SaifuMak Add Custom C…5.4
- CVE-2025-62109Insertion of Sensitive Information Into Sent Data vulnerabil…5.3
- CVE-2025-62110Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-62111Improper Neutralization of Input During Web Page Generation …6.5
- CVE-2025-62112Cross-Site Request Forgery (CSRF) vulnerability in Merv Barr…4.3
- CVE-2025-62113Cross-Site Request Forgery (CSRF) vulnerability in emendo_se…4.3
- CVE-2025-62114Exposure of Sensitive System Information to an Unauthorized …5.3
- CVE-2025-62115Missing Authorization vulnerability in ThemeBoy Hide Plugins…4.3
Are you affected by CVE-2025-6211?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
