{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/vendors/kotaemon/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:kotaemon:kotaemon:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.4,"id":"CVE-2026-82281"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Kotaemon (\u003c= 0.12.0)"],"_cs_severities":["high"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Kotaemon"],"content_html":"\u003cp\u003eKotaemon through version 0.12.0 is susceptible to an authorization bypass vulnerability located in the conversation management functions of control.py. The affected functions include select_conv, delete_conv, rename_conv, and on_set_public_conversation. The application fails to perform adequate validation of conversation ownership when these functions are called, allowing an unauthenticated or low-privileged attacker to supply arbitrary conversation identifiers. By manipulating these identifiers, an attacker can read sensitive chat histories, rename existing conversations, or perform unauthorized deletions of historical data. This vulnerability poses a significant risk to data privacy and integrity within the application, as it circumvents intended access controls over user communications.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows unauthorized access to private user chat histories and the ability to perform destructive actions such as deleting or renaming conversations. This impact is significant in multi-user environments where conversation isolation is a security requirement. Organizations utilizing Kotaemon for internal AI-powered document analysis and chat should treat this as a high-risk issue until patches are applied.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade to a version of Kotaemon beyond 0.12.0 as soon as a patch is made available by the maintainers.\u003c/li\u003e\n\u003cli\u003eAudit access logs for unexpected sequences of calls to control.py functions (select_conv, delete_conv, rename_conv) originating from a single user session that access multiple distinct conversation IDs.\u003c/li\u003e\n\u003cli\u003eImplement network-level restrictions to ensure that instances of Kotaemon are not exposed to untrusted users or the public internet.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-29T01:35:40Z","date_published":"2026-08-29T01:35:40Z","id":"https://feed.craftedsignal.io/briefs/2026-08-kotaemon-auth-bypass/","summary":"Kotaemon through version 0.12.0 contains an authorization bypass vulnerability allowing unauthorized users to access, modify, or delete chat histories belonging to others.","title":"Authorization Bypass in Kotaemon Conversation Management","url":"https://feed.craftedsignal.io/briefs/2026-08-kotaemon-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Kotaemon","version":"https://jsonfeed.org/version/1.1"}