Resource Exhaustion Vulnerability in Cinnamon kotaemon by Cinnamon
CVE-2025-63914
6.5MEDIUM
What is CVE-2025-63914?
A vulnerability exists in the Cinnamon kotaemon version 0.11.0 related to the _may_extract_zip function in the ui.py file. This vulnerability allows unauthorized users to upload ZIP files without proper content validation. While the server attempts to clear any extracted data in temporary folders after each extraction, an attacker can exploit this by uploading a specially crafted ZIP bomb. Such an attack may unnecessarily consume server resources during the decompression process, leading to potential service interruptions and excessive disk space occupation. This vulnerability poses a risk to system availability and can be exploited by any user with file upload permissions.
