Known Vulnerabilities for Kotaemon by Cinnamon AI
Listed below are 3 of the newest known vulnerabilities associated with "Kotaemon" by "Cinnamon AI".
These CVEs are retrieved based on exact matches on listed software, hardware, and vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed software information are still displayed.
Data on known vulnerable versions is also displayed based on information from known CPEs
Known Vulnerabilities
| CVE | Shortened Description | Severity | Publish Date | Last Modified |
|---|---|---|---|---|
| CVE-2026-86867 json | Cinnamon's Kotaemon (all versions up to and including v0.12.0) multi-user chat interface contains multiple vulnerabilities du... | Not Provided | 2026-09-23 | 2026-09-24 |
| CVE-2026-82281 json | Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_se... | Not Provided | 2026-08-28 | 2026-09-03 |
| CVE-2026-69098 json | kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unaut... | Not Provided | 2026-08-04 | 2026-08-05 |