Plaintext Password Storage Vulnerability in Kotaemon by Cinnamon
CVE-2025-56527
7.5HIGH
What is CVE-2025-56527?
The Kotaemon 0.11.0 application by Cinnamon exposes sensitive user credentials by storing passwords in plaintext within the client’s localStorage. This vulnerability can lead to unauthorized access if an attacker gains access to the localStorage data. Proper sanitization and encryption measures are critical to securing sensitive information and preventing potential data breaches.
