


Perceptive Security
SOC/SIEM Consultancy

kotaemon through 0.12.0 contains an insecure deserialization vulnerability in the check_connection endpoint that allows unauthenticated attackers to instantiate…
Published:
3 August 2026 at 22:00:00
Alert date:
4 August 2026 at 17:02:19
Source:
nvd.nist.gov
Web Technologies, Zero-Day Vulnerabilities
kotaemon versions through 0.12.0 are affected by an insecure deserialization vulnerability in the check_connection endpoint. Unauthenticated attackers can exploit this flaw by supplying crafted YAML/JSON input containing a __type__ field to instantiate arbitrary Python classes. By overriding the __type__ field with subprocess.check_output and supplying arbitrary arguments, attackers can achieve remote code execution with the privileges of the application process. No authentication is required to exploit this vulnerability, making it particularly dangerous for exposed instances. The vulnerability is tracked as CVE-2026-69098 and has been reported via GitHub issues and documented by VulnCheck. The issue affects the open-source RAG-based document QA platform kotaemon developed by Cinnamon. Exploitation could lead to full system compromise depending on the application's runtime privileges. Users are advised to update beyond version 0.12.0 or apply mitigations immediately.
Technical details
Mitigation steps:
Affected products:
kotaemon 0.12.0
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-69098
https://github.com/Cinnamon/kotaemon/issues/844
https://www.vulncheck.com/advisories/kotaemon-unauthenticated-remote-code-execution-via-insecure-deserialization
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
