Historical version

This is version 2, as it stood on . It is not what this organization currently publishes — read the current version.

VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

CERT Coordination Center Version 2 imported change

Imported from official source

Overview Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. …

This version

Version
2 of 3
Recorded
September 23, 2026 20:00
Change
Imported change
Content hash
9544c972af503603b982581dd9a3cfe1
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.