kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges.
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
History
Tue, 04 Aug 2026 15:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a __type__ field. Attackers can exploit this to override the __type__ field with subprocess.check_output and arbitrary arguments, achieving remote code execution with application process privileges. | |
| Title | kotaemon 0.12.0 Unauthenticated Remote Code Execution via Insecure Deserialization | |
| First Time appeared |
Cinnamon
Cinnamon kotaemon |
|
| Weaknesses | CWE-502 | |
| CPEs | cpe:2.3:a:cinnamon:kotaemon:0.0.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.1.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.2.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.1:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.2:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.3:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.4:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.5:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.3.6:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.0:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.1:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.2:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.3:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.4:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.5:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.6:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.7:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.8:*:*:*:*:*:*:* cpe:2.3:a:cinnamon:kotaemon:0.4.9:*:*:*:*:*:*:* |
|
| Vendors & Products |
Cinnamon
Cinnamon kotaemon |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: VulnCheck
Published:
Updated: 2026-08-04T15:15:06.018Z
Reserved: 2026-08-03T10:44:14.336Z
Link: CVE-2026-69098
No data.
No data.
No data.
OpenCVE Enrichment
Updated: 2026-08-04T17:00:12Z
Weaknesses