Insecure Deserialization in Kotaemon Affects Unauthenticated Access
CVE-2026-69098
Key Information:
Badges
What is CVE-2026-69098?
Kotaemon versions up to 0.12.0 are susceptible to an insecure deserialization flaw in the check_connection endpoint. This vulnerability permits unauthenticated attackers to manipulate input—crafted YAML or JSON with a type field—allowing them to instantiate arbitrary Python classes. By exploiting this weakness, attackers can modify the type field to execute subprocess.check_output with arbitrary parameters, leading to remote code execution with the privileges of the application process.
Affected Version(s)
kotaemon 0 <= 0.12.0
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
References
CVSS V4
Timeline
- 🟡
Public PoC available
- 👾
Exploit known to exist
Vulnerability published
Vulnerability Reserved
