VU#754548: Cinnamon's Kotaemon contains improper authorization checks in Kotaemon multi‑user chat handlers

CERT Coordination Center Version 3 imported change current

Imported from official source

Cinnamon's Kotaemon (all versions up to v0.12.0) multi‑user chat interface does not verify conversation ownership when loading a conversation. Any authenticated user can read, delete, rename, or overwrite another user’s conversation data by supplying the correct ID. This results in high‑impact confidentiality, integrity, and availability violations. …

This version

Version
3 of 3
Recorded
September 24, 2026 20:00
Change
Imported change
Content hash
ad0ff90b4550cac86596193190fbb31a
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.