Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qgc-qr9j-76rw

Опубликовано: 28 авг. 2026
Источник: github
Github: Не прошло ревью
CVSS4: 9.1
CVSS3: 7.4

Описание

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

EPSS

Процентиль: 18%
0.00261
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-639

Связанные уязвимости

CVSS3: 7.4
nvd
22 дня назад

Kotaemon through 0.12.0 fails to properly validate conversation ownership in select_conv, delete_conv, rename_conv, and on_set_public_conversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.

EPSS

Процентиль: 18%
0.00261
Низкий

9.1 Critical

CVSS4

7.4 High

CVSS3

Дефекты

CWE-639