Cinnamon

    Dashboard / Vendors

    Products: 1
    Vulnerabilities: 5
    Known Exploited: 0
    1
    Critical Level Threats
    2
    High Level Threats
    2
    Medium Level Threats
    0
    Low Level Threats

    Vulnerabilities

    100806040200
    JanFebMarAprMayJunJulAugSepOctNovDec
    Critical Level Threats
    High Level Threats
    Medium Level Threats
    Low Level Threats

    Products Security index

    Actions
    Items Per Page

    Vulnerabilities

    CVE-2026-82281

    Kotaemon Missing Ownership Check in Conversation Functions

    Last Modified: Aug 31, 2026
    Published: Aug 28, 2026

    CVE-2026-69098

    kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization

    Last Modified: Aug 05, 2026
    Published: Aug 04, 2026

    CVE-2025-63914

    An issue was discovered in Cinnamon kotaemon 0.11.0. The _may_extract_zip function in the \libs\ktem\ktem\index\file\ui.py file does not check the contents of uploaded ZIP files. Although the contents are extracted into a temporary folder that is cleared before each extraction, successfully uploading a ZIP bomb could still cause the server to consume excessive resources during decompression. Moreover, if no further files are uploaded afterward, the extracted data could occupy disk space and potentially render the system unavailable. Anyone with permission to upload files can carry out this attack.

    Last Modified: Dec 30, 2025
    Published: Nov 24, 2025

    CVE-2025-56526

    Cross site scripting (XSS) vulnerability in Kotaemon 0.11.0 allowing attackers to execute arbitrary code via a crafted PDF.

    Last Modified: Dec 02, 2025
    Published: Nov 18, 2025

    CVE-2025-56527

    Plaintext password storage in Kotaemon 0.11.0 in the client's localStorage.

    Last Modified: Dec 02, 2025
    Published: Nov 18, 2025
    Items Per Page
    Cinnamon Vulnerabilities & Security CVEs | CVE-DB