CVE-2026-82281
Kotaemon through 0.12.0 fails to properly validate conversation ownership in selectconv, deleteconv, renameconv, and onsetpublicconversation functions in control.py. Attackers can read other users' chat histories, delete conversations, or rename conversations by supplying arbitrary conversation identifiers without proper authorization checks.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82281.json, https://nvd.nist.gov/vuln/detail/CVE-2026-82281, https://www.vulncheck.com/advisories/kotaemon-missing-ownership-check-in-conversation-functions, https://github.com/Cinnamon/kotaemon/issues/846, https://github.com/Cinnamon/kotaemon, https://github.com/Cinnamon/kotaemon/blob/9ad3e4e49aa35b8acddd235918a5d9753c1cfdf9/libs/ktem/ktem/pages/chat/control.py