GHSA-4qgc-qr9j-76rwCriticalCVSS 7.4

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv,...

Published
August 28, 2026
Last Modified
August 28, 2026

🔗 CVE IDs covered (1)

📋 Description

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

🔗 References (6)