Medium severity5.3NVD Advisory· Published Jul 7, 2025· Updated Jun 17, 2026
CVE-2025-3044
CVE-2025-3044
Description
A vulnerability in the ArxivReader class of the run-llama/llama_index repository, versions up to v0.12.22.post1, allows for MD5 hash collisions when generating filenames for downloaded papers. This can lead to data loss as papers with identical titles but different contents may overwrite each other, preventing some papers from being processed for AI model training. The issue is resolved in version 0.12.28.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected packages
Versions sourced from the GitHub Security Advisory.
| Package | Affected versions | Patched versions |
|---|---|---|
llama-index-readers-papersPyPI | < 0.3.1 | 0.3.1 |
Affected products
3- Range: unspecified
Patches
Vulnerability mechanics
References
5- github.com/run-llama/llama_index/commit/0008041e8dde8e519621388e5d6f558bde6ef42envdPatchWEB
- huntr.com/bounties/80182c3a-876f-422f-8bac-38267e0345d6nvdExploitThird Party AdvisoryWEB
- github.com/advisories/GHSA-p7j4-jwjf-5x9wghsaADVISORY
- nvd.nist.gov/vuln/detail/CVE-2025-3044ghsaADVISORY
- github.com/run-llama/llama_index/commit/f69e1c0e7579228fec4cfaf716e4f951e131de77ghsaWEB
News mentions
0No linked articles in our index yet.