Junglewise Threat Intelligence

CVE-2026-69098: kotaemon insecure deserialization in check_connection endpoint

CVE-2026-69098 · Severity: critical · CVSS 9.8 · Published 2026-08-04

Executive brief

kotaemon is a platform for building AI applications that integrates language models and retrieval systems. An unauthenticated attacker can send specially crafted requests to the /check_connection endpoint to execute arbitrary operating system commands on the server with the privileges of the kotaemon application process. No login credentials or API keys are required, and command output is returned directly to the attacker in the HTTP response.

Technical details

The vulnerability is an insecure deserialization flaw (CWE-502) in the /check_connection endpoint of kotaemon's Gradio-based API. The endpoint accepts user-supplied YAML/JSON input, loads it without validation, and passes it to a deserialize() function with safe=False that instantiates arbitrary Python classes via importlib.import_module() and getattr(). An attacker can override the __type__ field with subprocess.check_output and provide shell command arguments to achieve remote code execution. The endpoint is publicly accessible with no server-side authentication checks despite the application having a UI-layer login mechanism. Attack preconditions are minimal: only network reachability to the Gradio endpoint is required, and no user interaction is needed.

Affected products

  • Cinnamon kotaemon through 0.12.0

Timeline

  • 2026-08-04: disclosed

References

Related threats