kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.
History

Tue, 04 Aug 2026 15:45:00 +0000

Type Values Removed Values Added
Description kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.
Title kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization
First Time appeared Cinnamon
Cinnamon kotaemon
Weaknesses CWE-502
CPEs cpe:2.3:a:cinnamon:kotaemon:0.0.0:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.1.0:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.2.0:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.3.0:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.3.1:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.3.2:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.3.3:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.3.4:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.3.5:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.3.6:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.0:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.1:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.2:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.3:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.4:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.5:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.6:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.7:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.8:*:*:*:*:*:*:*
cpe:2.3:a:cinnamon:kotaemon:0.4.9:*:*:*:*:*:*:*
Vendors & Products Cinnamon
Cinnamon kotaemon
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-04T15:15:06.018Z

Reserved: 2026-08-03T10:44:14.336Z

Link: CVE-2026-69098

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T17:00:12Z