Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-p7j4-jwjf-5x9w

Опубликовано: 07 июл. 2025
Источник: github
Github: Прошло ревью
CVSS3: 5.3

Описание

LlamaIndex vulnerability in ArxivReader class can cause MD5 hash collisions

A vulnerability in the ArxivReader class of the run-llama/llama_index repository allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in llama-index-readers-papers version 0.3.1 (in llama-index 0.12.28).

Пакеты

Наименование

llama-index-readers-papers

pip
Затронутые версииВерсия исправления

< 0.3.1

0.3.1

EPSS

Процентиль: 15%
0.00049
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-440

Связанные уязвимости

CVSS3: 5.3
redhat
около 1 месяца назад

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in version 0.12.28.

CVSS3: 5.3
nvd
около 1 месяца назад

A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in version 0.12.28.

CVSS3: 5.3
fstec
около 1 месяца назад

Уязвимость класса ArxivReader фреймворка для работы с большими языковыми моделями (LLM) LlamaIndex, позволяющая нарушителю оказать воздействие на целостность защищаемой информации

EPSS

Процентиль: 15%
0.00049
Низкий

5.3 Medium

CVSS3

Дефекты

CWE-440