kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.
Metrics
Affected Vendors & Products
References
History
Tue, 04 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges. | |
| Title | kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization | |
| First Time appeared |
Cinnamon
Cinnamon kotaemon |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:cinnamon:kotaemon:0.0.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.1.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.2.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.1:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.2:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.3:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.4:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.5:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.6:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.1:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.2:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.3:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.4:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.5:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.6:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.7:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.8:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.9:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cinnamon
Cinnamon kotaemon |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-04T15:15:06.018Z
Reserved: 2026-08-03T10:44:14.336Z
Link: CVE-2026-69098
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T17:00:12Z