CVE-2026-69098
kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the checkconnection endpoint that allows unauthenticated attackers to instantiate arbitrary Python classes by supplying crafted YAML/JSON input with a type field. Attackers can exploit this to override the type field with subprocess.checkoutput and arbitrary arguments, achieving remote code execution with application process privileges.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/69xxx/CVE-2026-69098.json, https://nvd.nist.gov/vuln/detail/CVE-2026-69098, https://www.vulncheck.com/advisories/kotaemon-unauthenticated-remote-code-execution-via-insecure-deserialization, https://github.com/Cinnamon/kotaemon, https://github.com/Cinnamon/kotaemon/issues/844