Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
References
Configurations
No configuration.
History
No history.
Information
Published : 2026-08-28 20:20
Updated : 2026-08-31 20:17
NVD link : CVE-2026-82281
Mitre link : CVE-2026-82281
CVE.ORG link : CVE-2026-82281
JSON object : View
Products Affected
No product.
CWE
CWE-639
Authorization Bypass Through User-Controlled Key
