« Volver al listado

Cinnamon

Cinnamon Kotaemon: vulnerabilidades y CVE

Cinnamon Kotaemon tiene 7 vulnerabilidades publicadas, 6 de ellas en los últimos 12 meses. 2 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE7
Últimos 12 meses6
Críticas2
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2026-86867Media (6.5)0.18%—23 sept 2026
Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities due to incorrect authorization and improper access controls. There are four handler methods in…
CVE-2026-82281Crítica (9.1)0.33%—28 ago 2026
Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories,…
CVE-2026-69098Crítica (9.3)0.91%—4 ago 2026
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON…
CVE-2025-63914Media (6.5)0.36%—24 nov 2025
An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into…
CVE-2025-56527Alta (7.5)0.43%—18 nov 2025
Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.
CVE-2025-56526Media (6.1)0.41%—18 nov 2025
Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.
CVE-2025-53358Media (6.5)0.46%—2 jul 2025
kotaemon is an open-source RAG-based tool for document comprehension. From versions 0.10.6 and prior, in libs/ktem/ktem/index/file/ui.py, the index_fn method accepts both URLs and local file paths without validation.…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1190 Exploit Public-Facing Application3
  2. T1005 Data from Local System2
  3. T1059 Command and Scripting Interpreter1
  4. T1210 Exploitation of Remote Services1
  5. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.