Historical version

This is version 1, as it stood on . It is not what this organization currently publishes — read the current version.

VU#754548: Cinnamon's kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

CERT Coordination Center Version 1 original

Imported from official source

Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. …

This version

Version
1 of 3
Recorded
September 23, 2026 18:00
Change
Initial
Content hash
1cc7c23b1c5d1532298010bbacb5a37e
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.