All 4 CVE vulnerabilities found in kotaemon, with AI-generated Chinese analysis, references, and POCs.
Vendor: Cinnamon
| CVE ID | Title | CVSS | Severity | Published |
|---|---|---|---|---|
| CVE-2026-86867 | Cinnamon's kotaemon contains improper authorization checks in multi‑user chat handlers | - | - | 2026-09-23 |
| CVE-2026-82281 | Kotaemon Missing Ownership Check in Conversation Functions CWE-639 | 7.4 | High | 2026-08-28 |
| CVE-2026-69098 | kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization CWE-502 | 9.8 | Critical | 2026-08-04 |
| CVE-2025-53358 | kotaemon Vulnerable to Path Traversal via Link Upload CWE-22 | 6.5 | Medium | 2025-07-02 |
All 4 known CVE vulnerabilities affecting kotaemon with full Chinese analysis, references, and POCs where available.