CyberAlerts is shutting down on June 30th, 2025. Thank you for your support!

CVE-2025-21604: LangChain4j-AIDeepin Using MD5 to Hash files may cause file upload conflicts

6.9 CVSS

Description

LangChain4j-AIDeepin is a Retrieval enhancement generation (RAG) project. Prior to 3.5.0, LangChain4j-AIDeepin uses MD5 to hash files, which may cause file upload conflicts. This issue is fixed in 3.5.0.

Classification

CVE ID: CVE-2025-21604

CVSS Base Severity: MEDIUM

CVSS Base Score: 6.9

Affected Products

Vendor: moyangzhan

Product: langchain4j-aideepin

Exploit Prediction Scoring System (EPSS)

EPSS Score: 0.04% (probability of being exploited)

EPSS Percentile: 11.48% (scored less or equal to compared to others)

EPSS Date: 2025-02-04 (when was this score calculated)

References

https://github.com/moyangzhan/langchain4j-aideepin/security/advisories/GHSA-cv5r-73vf-8x7v
https://github.com/moyangzhan/langchain4j-aideepin/commit/3cf625c5044a151a8cbcbdf98e10b4b46b8a975a

Timeline